Impact
The TutorStarter WordPress theme prior to version 4.0.4 contains an AJAX registration handler that ignores the site’s user registration setting. An unauthenticated visitor can invoke this handler and create a WordPress account even when the global registration option is disabled. The flaw is an improper enforcement of authorization controls, allowing attackers to gain authenticated access without any credentials. This can lead to unauthorized users creating accounts that may have privileged roles depending on site configuration, potentially opening the door to further attacks or a broader disruption of the site’s user management. The weakness can be classified as an improper authorization flaw.
Affected Systems
WordPress sites using the TutorStarter theme with a version older than 4.0.4 are vulnerable. The theme is identified by the CNA as "TutorStarter". Sites running any version before the 4.0.4 release date cannot rely on the registration restriction setting to prevent new account creation via the AJAX endpoint.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation campaigns have been recorded yet. The likely attack vector is remote, with an attacker sending a crafted AJAX request from any external location. No special network conditions are required beyond the ability to reach the WordPress site, and the bypass does not require authentication or privileged access, making it easily exploitable by unauthenticated attackers. The impact is limited to the one site that hosts the vulnerable theme, but in a multi‑tenant environment with shared infrastructure the compromise could affect other sites on the same server if the attacker abuses the newly created accounts.
OpenCVE Enrichment