๐Ÿ” CVE Alert

CVE-2026-104671

MEDIUM 5.3

TutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAX

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.

Vendor unknown
Product tutorstarter
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown tutorstarter

Be the first to know when new medium vulnerabilities affecting unknown tutorstarter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / TutorStarter
0 < 4.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6ecea67e-8019-4ef2-bd27-a9da7dc27d43/

Credits

Alexander Jurkschat WPScan