CVE-2025-15100Disclosure

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_panel_ajax_update_profile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Disclouser: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-02-08); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-02-08: 5Mentions · 2026-02-09: 1Mentions · 2026-02-10: 1Mentions · 2026-02-13: 1PoC Mentioned / Linked · 2026-02-08: 1Active Exploitation · 2026-02-09: 1Patch / Workaround · 2026-02-08: 1Technical Details · 2026-02-08: 2Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-13: 102-0802-0902-1002-13
Signal classification3 categories
Disclosure
675.0%
Disclouser
112.5%
General
112.5%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-085
Disclosure3Disclouser1General1
2026-02-091
Disclosure1
2026-02-101
Disclosure1
2026-02-131
Disclosure1
Full discourse8 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-15100 - High The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary... https://www.thehackerwire.com/vulnerability/CVE-2025-15100/ https://t.co/hxZEJ3UqPx

    Post summary

    A high‑severity privilege escalation flaw was disclosed in the JAY Login & Register WordPress plugin; no PoC, exploit, or patch details are provided.

    1001075
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15100 The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a… https://www.cve.org/CVERecord?id=CVE-2025-15100

    Post summary

    The CVE-2025-15100 disclosure states that the JAY Login & Register WordPress plugin is vulnerable to privilege escalation up to version 2.6.03.

    00010195
    56.5K followersView on X
  • transilienceai@transilienceai
    Disclouser

    @TheHackerWire For full advisory: Search "CVE-2025-15100 Wordfence" or check http://plugins.wordpress.org for changelog. If you're affected, test your site with the PoC (ethically) post-patch. #StaySafe #WordPressUpdates

    Post summary

    An advisory for CVE-2025-15100 in Wordfence urges users to patch and test their WordPress sites with the PoC after applying the fix.

    1000068
    316 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @TheHackerWire 🚨 CVE-2025-15100: JAY Login & Register Plugin Privilege Escalation Vulnerability 🚨

    Post summary

    The tweet announces the existence of CVE‑2025‑15100 as a privilege‑escalation vulnerability in the JAY Login & Register plugin, but offers no additional technical details or mitigation information.

    1000038
    316 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-15100 (CVSS:8.8, HIGH) is Awaiting Analysis. The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including..https://nvd.nist.gov/vuln/detail/CVE-2025-15100 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2025-15100, a privilege escalation vulnerability in the JAY Login & Register WordPress plugin with CVSS 8.8, and notes it is awaiting analysis.

    0000028
    171 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-15100: HIGH] WordPress JAY Login & Register plugin (up to v2.6.03) found with Privilege Escalation vulnerability enabling attackers to elevate privileges. #cybersecurity#cve,CVE-2025-15100,#cybersecurity https://cvefind.com/CVE-2025-15100

    Post summary

    A high‑severity privilege escalation vulnerability has been disclosed in WordPress JAY Login & Register plugin (up to v2.6.03), allowing attackers to elevate privileges.

    0000045
    583 followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 09, 2026 1. Critical 0-Day Remote Code Execution Vulnerability in BeyondTrust Remote Access A critical pre-authentication remote code execution vulnerability (CVE-2026-1731) has been disclosed in BeyondTrust Remote Support and Privileged Remote Access products. This flaw allows attackers to execute arbitrary code remotely without prior authentication, posing a severe risk to affected systems. Sources: Cvefeed, Gbhackers https://cybersecuritynews.com/beyondtrust-remote-access-products-0-day-vulnerability/ 2. TGR-STA-1030 Linux Rootkit Spies on 37 Nations in State-Aligned Campaign The TGR-STA-1030 threat actor has deployed a sophisticated Linux rootkit to conduct cyber espionage targeting government networks across 37 countries between November and December 2025. Multiple critical vulnerabilities, including CVE-2026-1731 and others, were exploited to facilitate stealthy infiltration and data exfiltration. Sources: Bleepingcomputer, Cvefeed https://securityonline.info/jackma-shadowguard-tgr-sta-1030-spies-on-37-nations-via-linux-rootkit/ 3. Two Critical Remote Code Execution Vulnerabilities in detronetdip E-commerce 1.0.0 Two severe vulnerabilities in detronetdip E-commerce 1.0.0 allow remote attackers to bypass authentication via add_seller.php and perform unrestricted file uploads via addadhar.php. Both exploits have been publicly disclosed, increasing the risk of unauthorized access and potential system compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2165 4. Notepad++ Hack, Office & ESXi 0-Day Vulnerabilities Fuel Ransomware Attacks Recent exploits targeting Notepad++, Microsoft Office, and VMware ESXi have introduced critical zero-day vulnerabilities actively leveraged in ransomware campaigns. These vulnerabilities pose significant risks to enterprise environments, demanding urgent patching and mitigation efforts. Sources: Cvefeed https://cybersecuritynews.com/cybersecurity-newsletter-weekly-february/ 5. Critical Privilege Escalation Vulnerabilities in JAY Login & Register Plugin <= 2.6.03 Two critical privilege escalation vulnerabilities affect the JAY Login & Register WordPress plugin versions up to 2.6.03. Authenticated users with Subscriber access and unauthenticated attackers can exploit these flaws to gain administrator privileges by manipulating user meta via AJAX functions. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-15100 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article announces a critical pre-authentication RCE vulnerability (CVE-2026-1731) in BeyondTrust Remote Access products, noting that it is actively exploited in the wild, but does not provide a PoC, patch, or exploit code.

    0000083
    54 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2025-15100 - jayarsiech - JAY Login &amp; Register - https://www.redpacketsecurity.com/cve-alert-cve-2025-15100-jayarsiech-jay-login-register/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-15100 #jayarsiech #jay-login-and-register

    Post summary

    The text announces a CVE alert for CVE-2025-15100 but does not provide any detailed technical information, PoC, exploit code, patch, or evidence of active exploitation.

    00000110
    3.5K followersView on X

Explore more