Authentication Bypass Vulnerability in Case Theme User Plugin for WordPress
CVE-2025-5821

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 August 2025

What is CVE-2025-5821?

The Case Theme User plugin for WordPress has a vulnerability that allows attackers to bypass authentication mechanisms. This issue arises in all versions up to and including 1.0.3, due to improper handling of user login processes, particularly through the facebook_ajax_login_callback(). This flaw enables unauthenticated users to gain administrative access by exploiting the existing accounts on the site, provided they have access to the corresponding administrative user's email.

Affected Version(s)

Case Theme User * <= 1.0.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Friderika Baranyai
.
CVE-2025-5821 : Authentication Bypass Vulnerability in Case Theme User Plugin for WordPress