Sceawere

Vulnerability Detail

CVE-2026-104671UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TutorStarter Unauthenticated Account Creation Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Unknown
Product
TutorStarter
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-08T11:16:44.303Z",
  "pubdate": "2026-10-08T11:16:44.303Z",
  "executiveSummary": "The TutorStarter WordPress theme contains an Improper Authorization vulnerability that allows for unauthorized user account creation.\nThe vulnerability originates in an AJAX registration handler that fails to validate the global WordPress 'users_can_register' setting.\nThis flaw permits unauthenticated remote attackers to bypass site registration restrictions and create new user accounts regardless of the administrator's configuration.\nSuccessful exploitation results in unauthorized user registration, which may lead to privilege escalation if the created accounts are assigned elevated roles or used as a vector for further attacks.\nThe vulnerability affects TutorStarter versions prior to 4.0.4.\nRisk implications include potential unauthorized data access, unauthorized system interaction, and the degradation of site integrity. No authentication is required to perform this action, and the attack vector is reachable over the network.",
  "technicalDetails": "The root cause of this vulnerability lies in an insecure implementation of an AJAX-based registration handler within the TutorStarter theme. The handler fails to perform a comprehensive check against the 'users_can_register' option stored in the WordPress database (wp_options table). In a standard WordPress installation, user registration functionality is governed by the 'Membership' settings; however, the vulnerable code path in TutorStarter directly processes registration requests without verifying this core security constraint.\nWhen an unauthenticated attacker sends a crafted request to the theme's vulnerable AJAX endpoint, the server-side script initializes the registration process. Because the handler lacks an authorization check to determine if the site currently allows new registrations, the function proceeds to instantiate a new user object using the provided input parameters. This effectively bypasses the application-level security policy that is intended to prevent unauthorized public account creation.\nThe exploitation flow is as follows: 1) An attacker identifies the exposed AJAX endpoint associated with the TutorStarter theme registration functionality. 2) The attacker crafts a request containing the necessary parameters to trigger the user creation logic (e.g., username, password, email). 3) The request is submitted to the server without any session tokens or authentication credentials. 4) The server-side handler executes the registration logic, omitting the mandatory check for the 'users_can_register' flag. 5) The database is updated, and a new user account is created for the attacker.\nThe component affected is the TutorStarter theme registration handler. This vulnerability is present in versions prior to 4.0.4. Since the endpoint is accessible via standard HTTP/HTTPS requests and does not require authentication, the attack surface is exposed to any remote user with network access to the target WordPress installation.\nPost-exploitation impact includes the presence of unauthorized accounts on the system. Depending on the theme's logic, these accounts may be created with default user roles. An attacker with a registered account may then attempt to exploit further vulnerabilities or leverage the account to conduct social engineering, access restricted areas, or potentially escalate privileges if other misconfigurations exist within the WordPress environment."
}
CVE-2026-104671: TutorStarter Unauthenticated Account Creation Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere