Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-14440. PoCs published by Nxploited.
AI-analyzed exploit summary This is a functional exploit for CVE-2025-14440, targeting an authentication bypass vulnerability in the JAY Login & Register WordPress plugin. The script automates nonce extraction and session cookie acquisition to bypass authentication for any user with a known ID.
Description
The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in the 'jay_login_register_process_switch_back' function with the 'jay_login_register_process_switch_back' cookie value. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.
Exploits (1)
This is a functional exploit for CVE-2025-14440, targeting an authentication bypass vulnerability in the JAY Login & Register WordPress plugin. The script automates nonce extraction and session cookie acquisition to bypass authentication for any user with a known ID.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H