CVE-2026-104671
TutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAX
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.
| Vendor | unknown |
| Product | tutorstarter |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown tutorstarter
Be the first to know when new medium vulnerabilities affecting unknown tutorstarter are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / TutorStarter
0 < 4.0.4
References
Credits
Alexander Jurkschat WPScan