---
id: CVE-2025-14440
title: >-
  The JAY Login & Register plugin for WordPress is vulnerable to authentication
  bypass in versions up to, and including, 2.4.01
summary: >-
  The JAY Login & Register plugin for WordPress is vulnerable to authentication
  bypass in versions up to, and including, 2.4.01. This is due to incorrect
  authentication checking in the 'jay_login_register_process_switch_back'
  function with…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-565
published: '2025-12-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14440'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/jay-login-register/tags/2.4.01/includes/jay-login-register-user-switching.php#L98
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3418754/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/928877a6-eeeb-4ed5-900b-9b1560e1bf87?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.00752
epssPercentile: 0.5351
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Nxploited/CVE-2025-14440'
  checkedAt: '2026-10-07T20:47:22.832Z'
exploitAvailable: true
ingestedAt: '2026-10-07T20:46:46.932Z'
---

## Overview

The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with the 'jay_login_register_process_switch_back' cookie value. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
