Security Alert Summary
The TutorStarter WordPress theme prior to version 4.0.4 contains a flaw in an AJAX registration handler that ignores the site-wide user registration setting. As a result, unauthenticated visitors can create WordPress user accounts even when registration is disabled.
CVE Details
- CVE ID:
CVE-2026-104671 - Affected component: TutorStarter WordPress theme
- Affected versions: Versions less than 4.0.4
- Published: October 8, 2026 at 11:16:44 AM UTC
- Last modified: October 8, 2026 at 11:16:44 AM UTC
- CVSS v3.1: Base score 5.3 (MEDIUM) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - Privileges required / Authentication: None required (PR:N)
- User interaction: None required (UI:N)
- Attack vector: Network (AV:N)
- Primary impact: Confidentiality: None; Integrity: Low; Availability: None
- CWE: CWE-862
Technical Details
The theme includes an AJAX-based registration handler that does not respect the site setting which disables user registration. Because that handler fails to check whether registration is allowed, unauthenticated requests can create new WordPress user accounts even when the administrator has disabled registrations from the settings. The CVE description identifies the issue as a missing enforcement of the site registration setting in one of the theme’s AJAX registration handlers.
The direct impact is the creation of user accounts by remote unauthenticated actors. The issue does not, based on the provided information, indicate privilege escalation beyond newly created accounts or other vulnerabilities in unrelated theme code.
How This Could Impact Your Website
On a multi-user site, the site owner or administrator may have disabled registrations to prevent unvetted accounts from being added. With this vulnerability, an external actor could create accounts that appear legitimate to internal staff or contractors. For example, an attacker could register multiple low-privilege accounts and use them to post content, access sections of the site available to registered users, or target specific staff with tailored phishing attempts using harvested or guessed email addresses.
Practical consequences include an increased volume of unauthorized accounts, potential exposure to targeted social engineering against editors or contributors, and extra administrative overhead to detect and remove bogus accounts. If you are unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review your setup.
Recommended Actions
- Update the affected theme to a patched version as soon as one is available.
- Temporarily review and remove any unexpected user accounts created around the time of the vulnerability disclosure.
- Review and reduce unnecessary user roles, especially contributor-level accounts.
- Enforce strong passwords and enable two-factor authentication for editors and administrators.
- Remove unused or unmaintained themes and plugins to reduce attack surface.
- Monitor site activity and logs for unusual registration or login behavior.
If youd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.