JAY Login & Register
JAY Login & Register has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 9.5, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 1 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Improper Privilege Management, behind 2 of the records (67%). Other recurring categories include Reliance On Cookies Without Validation And Integrity Checking.
Every one of the 3 issues recorded for JAY Login & Register has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. JAY Login & Register is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-15027JAY Login & Register <= 2.6.03 - Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_user
Read the full analysisVulnerability Records

JAY Login & Register
Author
jayarsiech
Developed with ❤️ in Iran. 🇮🇷 JAY Login & Register is not just a login plugin; it is a complete authentication, access control, and user management ecosystem for WordPress. While it creates a seamless Mobile OTP (One-Time Password) login and registration flow compatible with Digits, its true power lies in its Advanced Content Restriction and Granular Role Management capabilities. 🛡️ NEW: Advanced Role & Capability Management Take granular control over user permissions without extra plugins: * Visual Role Manager: Easily create, edit, and delete custom user roles with a clean, tabbed interface. * Granular Capability Assignment: Assign specific WordPress capabilities (Posts, Pages, Media, Comments, Categories, Tags, and 3rd-party plugin caps) to any role. * User-Specific Overrides: Grant or revoke specific capabilities for individual users directly from their profile page, independent of their assigned role. 🌟 NEW: Advanced User Panel & Profile Builder Transform user profiles with a powerful, drag-and-drop form builder: * Unlimited Custom Fields: Text, Select, Radio, Checkbox, and Jalali Date Picker. * Smart Conditional Logic: Show/hide fields dynamically based on User Meta (Server-side) or other field values (Client-side) with complex AND/OR rules. * Native Media Integration: Direct avatar uploads to the WordPress Media Library. * Bulletproof Security: All conditional logic is strictly re-validated on the server to prevent tampering. 🚀 NEW: Native Gravity Forms OTP Add-on Verify phone numbers directly inside any Gravity Form before submission: * Seamless Integration: Dedicated “JAY Mobile Verification” field in the GF editor. * AJAX Validation & Auto-Login: Verify OTPs without page reloads and optionally log in/register users instantly. * Built-in Anti-Fraud: Fully protected by JAY’s global IP/Phone Lockout system to prevent SMS bombing. Key Features Core Login & Registration * Smart Detection: Automatically routes new numbers to registration and existing numbers to login. * Multi-Method Login: Users can log in seamlessly using Mobile Number, Email, or Username. * Digits Compatibility: Seamlessly recognizes and logs in users previously registered with the Digits plugin. * Optional Identity Verification: Built-in duplicate prevention for National ID or Passport numbers. Powerful Content & Access Control * Inline & Redirect Locking: Use the [jay_content_lock] shortcode or Gutenberg Block to restrict content. Choose between a blurred preview with redirect, or an inline AJAX form that unlocks content instantly. * Post/Page Meta Box: Restrict entire posts or pages based on login status, specific user roles, or custom user meta keys. Advanced Security & Anti-Fraud * Multiple CAPTCHA Options: Disabled, Simple Math, Invisible Honeypot (with time-trap), or Google reCAPTCHA v3. * Brute-Force Protection: Configurable lockouts based on max failed attempts, duration, and blocking method (Phone, IP, or both). * Hide wp-login.php: Secure your site by completely hiding the default WordPress login page. Seamless User Experience (UX) * Smart Redirects: Automatically returns users to the page they were trying to access after login. * Modern Customizable Forms: Beautifully designed forms with optional logo upload and custom color styling. * Custom Logout URL: Create a user-friendly logout link (e.g., yoursite.com/logout). Powerful Admin Management * Admin Area Access Control: Restrict access to the WordPress dashboard (/wp-admin) based on specific user roles. * User Switching: Easily switch to any user’s account to view the site from their perspective. * Customizable User Columns: Adds sortable “Mobile Number” and “Jalali Registration Date” columns, and allows creating custom columns based on any user meta key. External Services This plugin connects to third-party services to provide its full range of features. These are optional and only active when configured by the site administrator. SMS Gateways (iPPanel, FarazSMS, Kavenegar, SMS.ir, MeliPayamak, RayganSMS): Sends the user’s mobile number to deliver SMS OTP codes. Privacy Policies Bale Messenger (Safir OTP): Sends the user’s mobile number to deliver app-based OTP codes as a cost-effective SMS alternative. Bale Developer Docs Google (reCAPTCHA v3 & OAuth): Processes IP and device data for bot protection and secure one-click authentication. Google Privacy Policy Eitaa (WebApp API): Secure data exchange with Eitaa servers for Mini App authentication. Eitaa Developer Docs
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C