Skip to content
September 13, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • CVE-2025-5821: Critical Authentication Bypass in WordPress Case Theme User Plugin Exploited in the Wild
  • Vulnerability Report

CVE-2025-5821: Critical Authentication Bypass in WordPress Case Theme User Plugin Exploited in the Wild

Do Son September 16, 2025 3 minutes read
0
Check Point VPN vulnerability exploited in the wild Check Point VPN exploit CVE-2026-50751 zero-day Checkmarx Breach Supply Chain Attack Ivanti EPMM RCE CVE-2026-1281 Modular DS Vulnerability CVE-2026-23550 D-Link RCE Vulnerability CVE-2026-0625 Christmas 2025 GreyNoise Campaign, Japan-Based Initial Access Broker React2Shell Zero-Day, APT Active Exploitation WordPress vulnerability, authentication bypass FreePBX, zero-day Trend Micro Apex One, Remote Code Execution BitoPro Hack, Crypto Theft UNC5337 - CVE-2022-47945 Safe{Wallet} hack Fortinet vulnerability, CVE-2024-21762, FortiGate attack Balloonfly, Play ransomware Ivanti EPMM CVE-2025-4427 and CVE-2025-4428
Add Daily CyberSecurity as a preferred source on Google

Hackers are exploiting a critical authentication bypass vulnerability in the Case Theme User plugin, a WordPress plugin with an estimated 12,000 active installations. This plugin is bundled in multiple premium themes, amplifying its reach across WordPress websites.

Track every WordPress CVE the moment it's exploited.

Get free email alerts →

Tracked as CVE-2025-5821 (CVSS 9.8), the flaw affects all versions up to and including 1.0.3 of the plugin. The root cause lies in the plugin’s facebook_ajax_login_callback() function, which mishandles authentication logic for Facebook-based social login.

Wordfence explains, “This vulnerability makes it possible for an unauthenticated attacker to gain access to any account on a site including accounts used to administer the site, if the attacker knows, or can find, the associated email address.”

As Wordfence details, “This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site which can easily be created by default through the temp user functionality, and access to the administrative user’s email.”

A patched version (1.0.4) was released on August 13, 2025, but exploitation began just one day after public disclosure on August 22.

Wordfence has confirmed that attackers are actively targeting this vulnerability at scale: “The Wordfence Firewall has already blocked over 20,900 exploit attempts targeting this vulnerability.”

The attack pattern is simple but dangerous. Threat actors first register a temporary user, then attempt to log in as an administrator by trying common email addresses like owner@, office@, or sales@victim-domain.com.

Top offending IP addresses include:

  • 2602:ffc8:2:105:216:3cff:fe96:129f (6,300+ blocked requests)
  • 146.70.186.142 (5,700+ blocked requests)
  • 107.175.179.8 (5,000+ blocked requests)

Wordfence observed attack spikes on August 23, 26, 30, and September 2, underscoring the urgency of patching.

Attackers typically:

  • Create a temporary user.
  • Exploit the authentication bypass to log in as an administrator.
  • Delete the temporary user to erase evidence.

Wordfence recommends reviewing log files for suspicious AJAX requests originating from the identified malicious IPs. However, they caution that “the absence of any such log entries does not guarantee that your website has not been compromised.”

To protect WordPress sites:

  • Update immediately to Case Theme User 1.0.4 or later.
  • Audit administrator accounts for unauthorized logins.
  • Review logs for abnormal AJAX requests tied to the vulnerability.

Wordfence strongly advises urgent patching: “We urge users to ensure their sites are updated with the latest patched version of Case Theme User, version 1.0.4 at the time of this writing, as soon as possible, as this vulnerability is under active exploitation.”

Related Posts:

  • WordPress Malware Alert: Fake Anti-Malware Plugin Grants Admin Access and Executes Remote Code
  • New WordPress Malware Masquerades as Legit Plugin with Data Exfiltration and RCE Capabilities
  • Breaking News: Widespread WordPress Plugin Compromise in Active Supply Chain Attack
  • WordPress Issues Urgent Security Update to Patch Multiple Vulnerabilities

Related coverage

  • Search Engine Exposed: Apache Solr Flaws Leak Data & Bypass Auth
  • 1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1)
  • 36,872 Exposed BMCs Leak Password Hashes and Face In-the-Wild Attacks via CVE-2013-4786
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: admin account takeover Authentication Bypass Case Theme User CVE-2025-5821 CVSS 9.8 cybersecurity hacker attacks Wordfence WordPress Vulnerability

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90558CVSS 9.8
    sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting...
  • CVE-2026-78159CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-85681CVSS 9.8
    The WP Component WordPress plugin through 2.2.4 does not have any capability...
  • CVE-2026-84171CVSS 9.8
    The WP images upload on piclect WordPress plugin through 1.0 does not...
  • CVE-2026-82845CVSS 9.9
    The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values...
  • CVE-2026-81402CVSS 9.8
    The DS Ad Rotator WordPress plugin through 0.8 does not perform any...
  • CVE-2026-77006CVSS 9.6
    The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied...
  • CVE-2026-77005CVSS 9.6
    The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a...
  • CVE-2026-75800CVSS 9.8
    The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.