๐Ÿ” CVE Alert

CVE-2026-105190

MEDIUM 5.3

Easy Digital Downloads < 3.7.1 - Unauthenticated Account Creation with Registration Disabled

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role.

Vendor unknown
Product easy digital downloads
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown easy digital downloads

Be the first to know when new medium vulnerabilities affecting unknown easy digital downloads are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / Easy Digital Downloads
0 < 3.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d167e184-af71-4ff8-8a2d-a665f7539fe4/

Credits

Rik de Kok WPScan