Vulnerabilities
CVE-2025-14440 - JAY Login & Register Plugin WordPress Authentication Bypass Vulnerability
CVE ID : CVE-2025-14440 Published : Dec. 13, 2025, 6:28 a.m. | 1 hour, 51 minutes ago Description : The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with the 'jay_login_register_process_switch_back' cookie value. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
WordPress
Impact:
authentication bypass
Source: Telegram CVE Monitor