User Account Creation Vulnerability in Easy Digital Downloads WordPress Plugin
CVE-2026-105190
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 8 October 2026
Badges
What is CVE-2026-105190?
The Easy Digital Downloads plugin for WordPress prior to version 3.7.1 contains a security flaw that permits unauthenticated users to create accounts without properly checking the user registration settings of the site. This issue enables unauthorized account creation and grants the created accounts the default user role, even if user registration features are disabled. Hence, a potential security risk is present, which could be exploited by malicious users.
Affected Version(s)
Easy Digital Downloads 0 < 3.7.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved