---
id: CVE-2026-104671
title: >-
  The TutorStarter WordPress theme before 4.0.4 does not respect the site's user
  registration setting in one of its AJAX registration handlers, allowing
  unauthenticated visitors to create WordPress user accounts even when user
  registration…
summary: >-
  The TutorStarter WordPress theme before 4.0.4 does not respect the site's user
  registration setting in one of its AJAX registration handlers, allowing
  unauthenticated visitors to create WordPress user accounts even when user
  registration…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: TutorStarter
affected:
  - TutorStarter < 4.0.4
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:51:18.123'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104671'
references:
  - url: 'https://wpscan.com/vulnerability/6ecea67e-8019-4ef2-bd27-a9da7dc27d43/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-08T10:53:57.447841Z'
ingestedAt: '2026-10-08T11:31:27.690Z'
---

## Overview

The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
