HomeSecurityWordPress: Critical vulnerability in Case Theme User plugin

WordPress: Critical vulnerability in Case Theme User plugin

A critical vulnerability (authentication bypass) in the WordPress plugin Case Theme User allows unauthorized attackers to gain administrative access to websitesby exploiting the social login feature.

WordPress vulnerability Case Theme User plugin

The vulnerability, tracked as CVE-2025-5821 (CVSS score 9.8), affects all versions of the plugin up to 1.0.3.

The vulnerability allows malicious users to completely bypass authentication mechanisms, granting unauthorized access to any user account, including administrator-level privileges. The prerequisite is that attackers know or can discover the target's email address.

What makes this vulnerability particularly dangerous is its simplicity — attackers can exploit it through simple HTTP requests without requiring sophisticated tools or extensive technical knowledge.

See also: Vulnerabilities in Spring Security Framework bypass authorization

Active exploitation began almost immediately after the vulnerability was publicly disclosed on August 22, 2025, with attackers launching attacks the following day.

Wordfence analysts discovered the vulnerability through its bug bounty program and noted that the company’s firewall has already blocked over 20,900 exploitation attempts. The rapid launch of the exploit demonstrates the vulnerability’s appeal to cybercriminals seeking quick access to WordPress websites.

WordPress: Critical vulnerability in Case Theme User plugin

It is worth noting that this particular plugin is linked to many premium themes, significantly expanding the attack surface beyond standalone installations.

Wordfence has observed that attackers are attempting to guess administrative email addresses using common patterns, such as admin@domain.com, owner@domain.com, and office@domain.com, indicating a systematic approach to exploiting multiple targets.

WordPress plugin Case Theme User: Infection mechanism and code analysis

The vulnerability stems from faulty logic in the facebook_ajax_login_callback() function within the Case_Theme_User_Ajax class.

The feature processes social login requests by creating user accounts based on the provided email addresses. However, it fails to properly validate the authentication status before granting access.

See also: Apple fixes vulnerability (backports) on old devices

The exploitation process involves two distinct phases. First, attackers register a temporary user account using their own email address via a POST request to /wp-admin/admin-ajax.php (with the action parameter set to facebook_ajax_login).

The malicious payload includes fabricated Facebook user data, creating a legitimate user session.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

WordPress: Critical vulnerability in Case Theme User plugin

In the second phase, attackers exploit the established session to authenticate themselves as the target victim. They submit another request using the same temporary username but substituting the email address victim's.

The vulnerable code retrieves the user via email, instead of verifying the original authentication token, effectively transferring session privileges to the target account.

See also: Zero-click RCE exploit in Linux kernel KSMBD

The update released in version 1.0.4 of Case Theme User addresses this vulnerability by implementing proper authentication verification before granting access rights.

Website administrators should immediately update to the latest version and check access logs for suspicious AJAX requests originating from known malicious IP addresses.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS