The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly logging a user in with the data that was previously verified through the facebook_ajax_login_callback(). This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site, and access to the administrative user's email.
History

Sun, 24 Aug 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Case-themes
Case-themes case Theme User
Wordpress
Wordpress wordpress
Vendors & Products Case-themes
Case-themes case Theme User
Wordpress
Wordpress wordpress

Sat, 23 Aug 2025 07:00:00 +0000

Type Values Removed Values Added
Description The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly logging a user in with the data that was previously verified through the facebook_ajax_login_callback(). This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site, and access to the administrative user's email.
Title Case Theme User <= 1.0.3 - Authentication Bypass via Social Login
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-08-23T06:43:35.611Z

Updated: 2025-08-23T06:43:35.611Z

Reserved: 2025-06-06T19:12:24.245Z

Link: CVE-2025-5821

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-08-23T07:15:32.507

Modified: 2025-08-23T07:15:32.507

Link: CVE-2025-5821

cve-icon Redhat

No data.