A critical vulnerability (authentication bypass) in the WordPress plugin Case Theme User allows unauthorized attackers to gain administrative access to websitesby exploiting the social login feature.

The vulnerability, tracked as CVE-2025-5821 (CVSS score 9.8), affects all versions of the plugin up to 1.0.3.
The vulnerability allows malicious users to completely bypass authentication mechanisms, granting unauthorized access to any user account, including administrator-level privileges. The prerequisite is that attackers know or can discover the target's email address.
What makes this vulnerability particularly dangerous is its simplicity — attackers can exploit it through simple HTTP requests without requiring sophisticated tools or extensive technical knowledge.
See also: Vulnerabilities in Spring Security Framework bypass authorization
Active exploitation began almost immediately after the vulnerability was publicly disclosed on August 22, 2025, with attackers launching attacks the following day.
Wordfence analysts discovered the vulnerability through its bug bounty program and noted that the company’s firewall has already blocked over 20,900 exploitation attempts. The rapid launch of the exploit demonstrates the vulnerability’s appeal to cybercriminals seeking quick access to WordPress websites.

It is worth noting that this particular plugin is linked to many premium themes, significantly expanding the attack surface beyond standalone installations.
Wordfence has observed that attackers are attempting to guess administrative email addresses using common patterns, such as admin@domain.com, owner@domain.com, and office@domain.com, indicating a systematic approach to exploiting multiple targets.
WordPress plugin Case Theme User: Infection mechanism and code analysis
The vulnerability stems from faulty logic in the facebook_ajax_login_callback() function within the Case_Theme_User_Ajax class.
The feature processes social login requests by creating user accounts based on the provided email addresses. However, it fails to properly validate the authentication status before granting access.
See also: Apple fixes vulnerability (backports) on old devices
The exploitation process involves two distinct phases. First, attackers register a temporary user account using their own email address via a POST request to /wp-admin/admin-ajax.php (with the action parameter set to facebook_ajax_login).
The malicious payload includes fabricated Facebook user data, creating a legitimate user session.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In the second phase, attackers exploit the established session to authenticate themselves as the target victim. They submit another request using the same temporary username but substituting the email address victim's.
The vulnerable code retrieves the user via email, instead of verifying the original authentication token, effectively transferring session privileges to the target account.
See also: Zero-click RCE exploit in Linux kernel KSMBD
The update released in version 1.0.4 of Case Theme User addresses this vulnerability by implementing proper authentication verification before granting access rights.
Website administrators should immediately update to the latest version and check access logs for suspicious AJAX requests originating from known malicious IP addresses.
