Description
The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with the 'jay_login_register_process_switch_back' cookie value. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.
Published: 2025-12-13
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The JAY Login & Register plugin for WordPress includes a critical flaw that allows unauthenticated users to bypass authentication by manipulating a specific cookie. When an attacker sets the 'jay_login_register_process_switch_back' cookie to a valid user ID, the plugin fails to perform a proper authentication check and logs the attacker in as that user. The vulnerability can lead to full administrative access to the site, compromising confidentiality, integrity, and potentially availability if the attacker performs destructive actions. The weakness is classified as CWE‑565, reflecting a break in authentication and privilege escalation. The CVSS score of 9.8 indicates a severe threat, underscoring the need for urgent mitigation.

Affected Systems

The affected product is the JAY Login & Register plugin from vendor jayarsiech. All releases up to and including version 2.4.01 are vulnerable. The issue exists in the WordPress environment where this plugin is deployed. No additional products or versions are listed as affected in the available data.

Risk and Exploitability

The exploit probability is low as shown by an EPSS score of less than 1%, yet the critical CVSS score and lack of mitigation options keep the risk high. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits as of the last update. The likely attack vector is remote: an adversary can craft a request or use browser developer tools to set the vulnerable cookie and trigger the authentication bypass. No additional system access or configuration changes are required beyond possessing a valid user identifier, which motivates attackers to enumerate user IDs through other means.

Generated by OpenCVE AI on April 21, 2026 at 17:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the JAY Login & Register plugin to a version newer than 2.4.01 that removes the vulnerable cookie handling – the fix is included in the latest releases.
  • If an update is not immediately possible, deactivate or delete the plugin to prevent exploitation while a patch is applied.
  • As a temporary workaround, modify the plugin’s code or server configuration to block the use of the 'jay_login_register_process_switch_back' cookie so that the authentication bypass cannot be triggered.

Generated by OpenCVE AI on April 21, 2026 at 17:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
References

Mon, 15 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Sat, 13 Dec 2025 04:45:00 +0000

Type Values Removed Values Added
Description The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with the 'jay_login_register_process_switch_back' cookie value. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.
Title JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
Weaknesses CWE-565
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:09:27.946Z

Reserved: 2025-12-10T12:22:08.723Z

Link: CVE-2025-14440

cve-icon Vulnrichment

Updated: 2025-12-15T15:30:24.318Z

cve-icon NVD

Status : Deferred

Published: 2025-12-13T16:16:49.570

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T17:15:25Z

Weaknesses