Authentication Bypass Vulnerability in Case Theme User Plugin for WordPress
CVE-2025-5821
9.8CRITICAL
What is CVE-2025-5821?
The Case Theme User plugin for WordPress has a vulnerability that allows attackers to bypass authentication mechanisms. This issue arises in all versions up to and including 1.0.3, due to improper handling of user login processes, particularly through the facebook_ajax_login_callback(). This flaw enables unauthenticated users to gain administrative access by exploiting the existing accounts on the site, provided they have access to the corresponding administrative user's email.
Affected Version(s)
Case Theme User * <= 1.0.3