JAY Login & Register <= 2.6.03 - Authenticated (Subscriber+) Privilege Escalation via jay_panel_ajax_update_profile
high
The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_panel_ajax_update_profile' function. This makes it possible for authenticated attackers, with Subscri...
- CVSS:
- 8.8
- Affected:
- up to 2.6.03
- Fixed in:
- 2.6.04
- Disclosed:
- Feb 7, 2026
CVE-2025-15100 on NVD →
JAY Login & Register <= 2.6.03 - Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_user
critical
The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_login_register_ajax_create_final_user' function. This makes it possible for unauthenticated attackers...
- CVSS:
- 9.8
- Affected:
- up to 2.6.03
- Fixed in:
- 2.6.04
- Disclosed:
- Feb 7, 2026
CVE-2025-15027 on NVD →
JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
critical
The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with the 'jay_login_register_process_switch_back' cookie value. This makes it possible...
- CVSS:
- 9.8
- Affected:
- up to 2.4.01
- Fixed in:
- 2.5.01
- Disclosed:
- Dec 12, 2025
CVE-2025-14440 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database