CVE-2026-105190 - Easy Digital Downloads < 3.7.1 - Unauthenticated Account Creation with Registration Disabled
CVE ID :CVE-2026-105190
Published : Oct. 8, 2026, 11:16 a.m. | 29 minutes ago
Description :The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 8, 2026, 11:16 a.m. | 29 minutes ago
Description :The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...