CVE-2026-107645 - Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter
CVE ID :CVE-2026-107645 Published : Oct. 10, 2026, 4:18 a.m. | 1 hour, 11 minutes ago Description :The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly...