Description
The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized account creation
Action: Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated visitor to create a WordPress user account even when the site’s registration is disabled. After account creation, the visitor receives a logged‑in session and the account is assigned the site’s default role. The impact is that any attacker can gain user access without permission, potentially enabling further exploitation based on the granted role.

Affected Systems

This flaw affects the Easy Digital Downloads WordPress plugin on all versions earlier than 3.7.1. No specific vendor product version range is omitted beyond the stated cutoff.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a direct HTTP request to the plugin’s endpoint that creates accounts; no authentication is required. An attacker could create multiple accounts, potentially escalating privileges if the default role grants administrative capabilities. The risk is present only when the plugin is installed and registration is disabled, but the lack of enforcement allows repeated successful attempts without detection.

Generated by OpenCVE AI on October 8, 2026 at 11:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Easy Digital Downloads to version 3.7.1 or later.
  • If upgrading is not possible, disable automatic account creation by adding a code snippet that checks the registration setting before account creation.
  • Configure the plugin or the site to deny all new user registrations if the default role is too permissive.

Generated by OpenCVE AI on October 8, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 08 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role.
Title Easy Digital Downloads < 3.7.1 - Unauthenticated Account Creation with Registration Disabled
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T10:59:17.044Z

Reserved: 2026-10-04T10:19:02.744Z

Link: CVE-2026-105190

cve-icon Vulnrichment

Updated: 2026-10-08T10:53:43.704Z

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:44.607

Modified: 2026-10-08T11:16:44.607

Link: CVE-2026-105190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T11:30:17Z

Weaknesses

No weakness.