Vulnerability Description
The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_login_register_ajax_create_final_user' function. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/jay-login-register/tags/2.5.01/includ
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b08198a6-10e8-44ca-a1c
FAQ
What is CVE-2025-15027?
CVE-2025-15027 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user met...
How severe is CVE-2025-15027?
CVE-2025-15027 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-15027?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.