Beveiligingsadvies

CVE-2025-15027

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-02-08 01:22:56
Laatst bijgewerkt 2026-04-08 17:15:55
Toegewezen door Wordfence
CVSS-score 9.8
Status PUBLISHED

Beschrijving

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_login_register_ajax_create_final_user' function. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.