CVE-2026-105190: Easy Digital Downloads < 3.7.1 - Unauthenticated Account Creation with Registration Disabled
The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Easy Digital Downloadsto a version that resolves this vulnerability.Fixed in 3.7.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
WordPress sites using Easy Digital Downloads versions earlier than 3.7.1 are exposed if they rely on the site's disabled user-registration setting to prevent account creation. The issue is reachable by unauthenticated users over the network.
What access does an attacker gain after exploiting it?
An attacker can create a WordPress account and receive a logged-in session. The new account is assigned the site's configured default role.
Does disabling WordPress user registration prevent exploitation?
No. Affected Easy Digital Downloads versions do not consult the site's user-registration setting before creating the account.
What version fixes the issue?
Upgrade Easy Digital Downloads to version 3.7.1 or later.