Impact
The vulnerability allows an unauthenticated visitor to create a WordPress user account even when the site’s registration is disabled. After account creation, the visitor receives a logged‑in session and the account is assigned the site’s default role. The impact is that any attacker can gain user access without permission, potentially enabling further exploitation based on the granted role.
Affected Systems
This flaw affects the Easy Digital Downloads WordPress plugin on all versions earlier than 3.7.1. No specific vendor product version range is omitted beyond the stated cutoff.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a direct HTTP request to the plugin’s endpoint that creates accounts; no authentication is required. An attacker could create multiple accounts, potentially escalating privileges if the default role grants administrative capabilities. The risk is present only when the plugin is installed and registration is disabled, but the lack of enforcement allows repeated successful attempts without detection.
OpenCVE Enrichment