External risk intelligence

JAY Login & Register WordPress Plugin Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-14440

The vulnerability exists in a WordPress login and registration plugin. Such plugins are designed to be internet-facing by default to enable user account management on public-facing websites, making the vulnerable authentication process directly accessible to any visitor over the network.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the JAY Login & Register plugin for WordPress, potentially allowing unauthorized access to user accounts, including administrator privileges, without requiring authentication. This issue arises from an error in how the plugin checks user credentials, meaning an attacker could potentially log in as any existing user if they know the user's ID. The main concern is to confirm if this plugin is in use and assess any potential exposure.

  • Attackers can bypass login to access user accounts.
  • Important for all public-facing WordPress sites.
  • Confirm plugin use and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could potentially bypass authentication on a WordPress site if they know an existing user's ID. This is possible because the JAY Login & Register plugin incorrectly checks authentication when switching users, allowing unauthenticated individuals to log in as any user, including administrators.

  • Entry condition: Unauthenticated.
  • Trigger point: Cookie manipulation.
  • Resulting risk: Unauthorized access to any user.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to bypass authentication and log in as any existing user, including administrators, by manipulating a specific cookie value, provided they know the target user's ID and the plugin is used to manage user accounts.

  • Site user accounts and administrator access.
  • Unauthenticated users could bypass login checks.
  • Unauthorized administrative control of the site.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners for WordPress sites are responsible for addressing this vulnerability, as it affects a plugin. The first practical step is to identify all WordPress instances, confirm their internet reachability and business criticality, and then coordinate with the relevant application owners to plan remediation.

  • WordPress application owners
  • Verify internet-facing WordPress instances
  • Plan remediation during maintenance windows

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the JAY Login & Register plugin?

This is an add-on for WordPress websites designed to manage user account creation and authentication. It simplifies how site visitors sign up or log in, acting as an interface between the user and the WordPress database. Because it handles sensitive account-related actions, it functions as a core gatekeeper for user sessions on sites where it is installed.

What does CWE-565 mean for CVE-2025-14440?

CWE-565 refers to reliance on a user-controlled input to determine a session or security state. In this specific vulnerability, the plugin improperly trusts a cookie value to verify identity. Instead of validating the user's password or secure token, the system incorrectly assumes the provided cookie is legitimate, effectively allowing an attacker to impersonate any user simply by requesting their account ID.

How is this authentication bypass triggered?

An attacker initiates the bypass by interacting with the specific cookie used by the plugin's user-switching function. The bug does not require the attacker to have an existing account, nor does it require knowledge of passwords. It only triggers when an attacker provides a known user ID through the vulnerable cookie, which causes the plugin to grant unauthorized access to that account.

Who should prioritize CVE-2025-14440?

Owners of any WordPress site using this plugin should prioritize this issue. According to Halo Surface Signal, this vulnerability is classified as external because the plugin is designed to be internet-facing to handle user logins. This means any site running the plugin is potentially accessible to unauthorized visitors over the network, making it a high-priority concern for public-facing web infrastructure.

How do I secure my site against this vulnerability?

Begin by auditing your WordPress environment to determine if the JAY Login & Register plugin is currently installed or active. Once identified, confirm the plugin version to see if it is affected. Since this is an application-level vulnerability, coordinate with your technical team to plan for updates or removal of the plugin, prioritizing those instances that are publicly accessible and critical to your site's operations.

References