Sceawere
Vulnerability Detail
CVE-2026-105190UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Easy Digital Downloads Improper Authorization
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Unknown
- Product
- Easy Digital Downloads
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-08T11:16:44.607Z",
"pubdate": "2026-10-08T11:16:44.607Z",
"executiveSummary": "The Easy Digital Downloads WordPress plugin contains a critical authorization flaw originating from a failure to validate global user registration settings during the account creation process. This vulnerability allows unauthenticated, remote attackers to bypass site-wide registration restrictions, effectively provisioning new user accounts and acquiring active authentication sessions.\nThe primary impact involves the unauthorized creation of accounts, which are automatically assigned the site's default user role. This poses a significant risk to site integrity and security, as it facilitates mass account registration, potential user enumeration, and the exploitation of default role privileges. The vulnerability is exploitable by any unauthenticated remote attacker, requiring no specific credentials or pre-existing access to the WordPress environment. Successful exploitation results in the creation of legitimate WordPress user entries, potentially allowing for downstream attacks if the default role possesses elevated permissions or if the site is susceptible to further user-based vulnerabilities.\nThis issue affects all versions of Easy Digital Downloads prior to 3.7.1. Administrators are advised to update the plugin immediately to ensure that registration policies are enforced as intended by the WordPress core configuration.",
"technicalDetails": "The vulnerability resides within the user registration logic of the Easy Digital Downloads (EDD) plugin, where the system fails to perform a necessary verification check against the WordPress global option 'users_can_register'. Under normal operating conditions, the WordPress framework prohibits the creation of new user accounts via standard endpoints if this setting is disabled.\nThe root cause of this flaw is an inadequate access control check within the EDD registration handling component. Instead of querying the WordPress API to determine if registration is permitted, the plugin logic proceeds to execute the account creation sequence autonomously. When an unauthenticated user submits a registration request, the plugin invokes internal functions to instantiate a new WP_User object and complete the signup process without ensuring the global 'users_can_register' flag is enabled.\nThe attack flow proceeds as follows: First, an unauthenticated attacker identifies the vulnerable registration endpoint or process within the EDD plugin. Second, the attacker submits a standard registration payload, which the plugin processes despite the site's explicit policy against public registration. Third, the plugin logic creates the new account, assigns the default WordPress user role (commonly 'subscriber'), and initializes a session for the user. Finally, the attacker is granted an active logged-in session on the target site.\nBecause the plugin does not gate this functionality behind an authentication check or a configuration verification, the attack requires zero privileges. The exposure is network-wide, as the endpoint is accessible to any remote entity capable of reaching the WordPress installation. The payload behavior is limited to the successful creation of a user entity within the database and the issuance of a valid authentication cookie to the attacker.\nThe post-exploitation impact is multifaceted. Beyond the unauthorized creation of accounts, this vulnerability can be leveraged to populate the user database with malicious entries, bypass administrative control over membership, or provide a foothold for further exploitation if the site’s default role has been modified to include excessive permissions. The lack of validation ensures that the plugin bypasses the security architectural expectations of the core WordPress platform."
}