Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability has been identified in the JAY Login & Register plugin for WordPress, potentially allowing unauthorized access to user accounts, including administrator privileges, without requiring authentication. This issue arises from an error in how the plugin checks user credentials, meaning an attacker could potentially log in as any existing user if they know the user's ID. The main concern is to confirm if this plugin is in use and assess any potential exposure.
- Attackers can bypass login to access user accounts.
- Important for all public-facing WordPress sites.
- Confirm plugin use and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker could potentially bypass authentication on a WordPress site if they know an existing user's ID. This is possible because the JAY Login & Register plugin incorrectly checks authentication when switching users, allowing unauthenticated individuals to log in as any user, including administrators.
- Entry condition: Unauthenticated.
- Trigger point: Cookie manipulation.
- Resulting risk: Unauthorized access to any user.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to bypass authentication and log in as any existing user, including administrators, by manipulating a specific cookie value, provided they know the target user's ID and the plugin is used to manage user accounts.
- Site user accounts and administrator access.
- Unauthenticated users could bypass login checks.
- Unauthorized administrative control of the site.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners for WordPress sites are responsible for addressing this vulnerability, as it affects a plugin. The first practical step is to identify all WordPress instances, confirm their internet reachability and business criticality, and then coordinate with the relevant application owners to plan remediation.
- WordPress application owners
- Verify internet-facing WordPress instances
- Plan remediation during maintenance windows