Description
The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized account creation via AJAX registration bypass
Action: Patch Immediately
AI Analysis

Impact

The TutorStarter WordPress theme prior to version 4.0.4 contains an AJAX registration handler that ignores the site’s user registration setting. An unauthenticated visitor can invoke this handler and create a WordPress account even when the global registration option is disabled. The flaw is an improper enforcement of authorization controls, allowing attackers to gain authenticated access without any credentials. This can lead to unauthorized users creating accounts that may have privileged roles depending on site configuration, potentially opening the door to further attacks or a broader disruption of the site’s user management. The weakness can be classified as an improper authorization flaw.

Affected Systems

WordPress sites using the TutorStarter theme with a version older than 4.0.4 are vulnerable. The theme is identified by the CNA as "TutorStarter". Sites running any version before the 4.0.4 release date cannot rely on the registration restriction setting to prevent new account creation via the AJAX endpoint.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation campaigns have been recorded yet. The likely attack vector is remote, with an attacker sending a crafted AJAX request from any external location. No special network conditions are required beyond the ability to reach the WordPress site, and the bypass does not require authentication or privileged access, making it easily exploitable by unauthenticated attackers. The impact is limited to the one site that hosts the vulnerable theme, but in a multi‑tenant environment with shared infrastructure the compromise could affect other sites on the same server if the attacker abuses the newly created accounts.

Generated by OpenCVE AI on October 8, 2026 at 11:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade TutorStarter to version 4.0.4 or later, which removes the flawed registration handler.
  • If an upgrade is not immediately possible, consider disabling the theme’s AJAX registration endpoint by adding a custom plugin or filter that blocks the specific AJAX action while maintaining the theme’s appearance.
  • As a temporary safeguard, review the permission levels granted to newly created roles and restrict any unnecessary privileges that could be abused by an attacker-created account.

Generated by OpenCVE AI on October 8, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-608

Thu, 08 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.
Title TutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAX
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T10:59:17.196Z

Reserved: 2026-10-02T07:59:21.083Z

Link: CVE-2026-104671

cve-icon Vulnrichment

Updated: 2026-10-08T10:53:45.497Z

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:44.303

Modified: 2026-10-08T11:16:44.303

Link: CVE-2026-104671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T11:30:17Z

Weaknesses

No weakness.