CVE-2026-104671: TutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAX
The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TutorStarter WordPress themeto a version that resolves this vulnerability.Fixed in 4.0.4
Event History
Frequently Asked Questions
Which sites are exposed to unauthorized account creation?
WordPress sites using TutorStarter versions earlier than 4.0.4 are exposed if the affected AJAX registration handler is reachable. The issue applies even when the site's normal user registration setting is disabled.
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction. They can create WordPress user accounts through the affected AJAX registration handler.
How can I determine whether my site is affected?
Check whether the site uses the TutorStarter theme and whether its version is earlier than 4.0.4. Review WordPress user accounts for unexpected registrations, particularly on sites where registration was intended to be disabled.