Themes Vulnerabilities
TutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAX
Description
The theme does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.
Proof of Concept
Affects Themes
References
CVE
Miscellaneous
Original Researcher
Alexander Jurkschat
Submitter
Alexander Jurkschat
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-10-06 (about 1 day ago)
Last Updated
2026-10-06 (about 1 day ago)