CVE-2025-14440 is an authentication bypass vulnerability in the JAY Login & Register WordPress plugin affecting versions up to and including 2.4.01. The issue is caused by incorrect authentication checking in the plugin function jay_login_register_process_switch_back, where the plugin relies on the jay_login_register_process_switch_back cookie value without sufficient validation/integrity checking. By manipulating this cookie and supplying/targeting a valid user ID, an unauthenticated remote attacker can cause the plugin to treat them as an authenticated session and log in as an arbitrary existing user (including administrators).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
jay_login_register_process_switch_back cookie and enforcing additional authentication hardening (e.g., MFA for admins) to limit post-bypass impact.Patch, then assume compromise.
jay_login_register_process_switch_back and properly validates the jay_login_register_process_switch_back cookie value. After updating, review for unauthorized logins/changes and rotate potentially exposed credentials/sessions as appropriate.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python exploit script (CVE-2025-14440.py) targeting the JAY Login & Register WordPress plugin (versions <=2.4.01) for CVE-2025-14440, an authentication bypass vulnerability. The exploit automates the process of extracting a required nonce from the target site, then crafts and sends a GET request with a special cookie and user ID to trigger the authentication bypass. If successful, it retrieves and saves session cookies for the specified user (including admin), enabling full account takeover. The script is operational, requiring only the target URL and user ID as input, and provides clear output and error handling. The repository also includes a README with detailed usage instructions, a license file, and a requirements.txt listing 'requests' as a dependency. No hardcoded endpoints are present; the target is specified at runtime. The only persistent file created is 'extracted_cookies.txt', which stores the results of successful exploitation.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass vulnerability in the JAY Login & Register WordPress plugin caused by incorrect authentication checking in the login/register functionality, affecting versions up to and including 2.4.01.
A critical authentication bypass vulnerability in the JAY Login & Register plugin for WordPress (up to and including version 2.4.01) allows unauthenticated attackers to log in as any user, including administrators, due to improper validation of a cookie value.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.