Skip to content
October 5, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • CVE-2025-5821: Critical Authentication Bypass in WordPress Case Theme User Plugin Exploited in the Wild
  • Vulnerability Report

CVE-2025-5821: Critical Authentication Bypass in WordPress Case Theme User Plugin Exploited in the Wild

Do Son September 16, 2025 3 minutes read
0
Check Point VPN vulnerability exploited in the wild Check Point VPN exploit CVE-2026-50751 zero-day Checkmarx Breach Supply Chain Attack Ivanti EPMM RCE CVE-2026-1281 Modular DS Vulnerability CVE-2026-23550 D-Link RCE Vulnerability CVE-2026-0625 Christmas 2025 GreyNoise Campaign, Japan-Based Initial Access Broker React2Shell Zero-Day, APT Active Exploitation WordPress vulnerability, authentication bypass FreePBX, zero-day Trend Micro Apex One, Remote Code Execution BitoPro Hack, Crypto Theft UNC5337 - CVE-2022-47945 Safe{Wallet} hack Fortinet vulnerability, CVE-2024-21762, FortiGate attack Balloonfly, Play ransomware Ivanti EPMM CVE-2025-4427 and CVE-2025-4428
Add Daily CyberSecurity as a preferred source on Google

Hackers are exploiting a critical authentication bypass vulnerability in the Case Theme User plugin, a WordPress plugin with an estimated 12,000 active installations. This plugin is bundled in multiple premium themes, amplifying its reach across WordPress websites.

Running Infra, AppSec, and SOC teams? Tag WordPress alerts by team automatically.

Try Team free for 14 days →

Tracked as CVE-2025-5821 (CVSS 9.8), the flaw affects all versions up to and including 1.0.3 of the plugin. The root cause lies in the plugin’s facebook_ajax_login_callback() function, which mishandles authentication logic for Facebook-based social login.

Wordfence explains, “This vulnerability makes it possible for an unauthenticated attacker to gain access to any account on a site including accounts used to administer the site, if the attacker knows, or can find, the associated email address.”

As Wordfence details, “This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site which can easily be created by default through the temp user functionality, and access to the administrative user’s email.”

A patched version (1.0.4) was released on August 13, 2025, but exploitation began just one day after public disclosure on August 22.

Wordfence has confirmed that attackers are actively targeting this vulnerability at scale: “The Wordfence Firewall has already blocked over 20,900 exploit attempts targeting this vulnerability.”

The attack pattern is simple but dangerous. Threat actors first register a temporary user, then attempt to log in as an administrator by trying common email addresses like owner@, office@, or sales@victim-domain.com.

Top offending IP addresses include:

  • 2602:ffc8:2:105:216:3cff:fe96:129f (6,300+ blocked requests)
  • 146.70.186.142 (5,700+ blocked requests)
  • 107.175.179.8 (5,000+ blocked requests)

Wordfence observed attack spikes on August 23, 26, 30, and September 2, underscoring the urgency of patching.

Attackers typically:

  • Create a temporary user.
  • Exploit the authentication bypass to log in as an administrator.
  • Delete the temporary user to erase evidence.

Wordfence recommends reviewing log files for suspicious AJAX requests originating from the identified malicious IPs. However, they caution that “the absence of any such log entries does not guarantee that your website has not been compromised.”

To protect WordPress sites:

  • Update immediately to Case Theme User 1.0.4 or later.
  • Audit administrator accounts for unauthorized logins.
  • Review logs for abnormal AJAX requests tied to the vulnerability.

Wordfence strongly advises urgent patching: “We urge users to ensure their sites are updated with the latest patched version of Case Theme User, version 1.0.4 at the time of this writing, as soon as possible, as this vulnerability is under active exploitation.”

Related Posts:

  • WordPress Malware Alert: Fake Anti-Malware Plugin Grants Admin Access and Executes Remote Code
  • New WordPress Malware Masquerades as Legit Plugin with Data Exfiltration and RCE Capabilities
  • Breaking News: Widespread WordPress Plugin Compromise in Active Supply Chain Attack
  • WordPress Issues Urgent Security Update to Patch Multiple Vulnerabilities

Related coverage

  • AI-Discovered Flaw: Redis Flaw (CVE-2025-62507) Allows Remote Code Execution via Stack Buffer Overflow
  • CVE-2026-19478: GitLab Flaw Exploited in the Wild, PoC Public
  • Red Hat ACM Fixes Five Critical Flaws, Including CVE-2026-72526 RCE Bug (CVSS 9.9)
  • FreeBSD DHCP Client Flaw Opens Door to Remote Code Execution as Root Privilege
  • Critical Triofox Zero-Day (CVE-2025-12480) Under Active Exploit: Host Header Bypass Allows Unauthenticated Admin Takeover
  • Unmasking DarkSword: GTIG Exposes Full-Chain iOS Exploit Used by Global Spies
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: admin account takeover Authentication Bypass Case Theme User CVE-2025-5821 CVSS 9.8 cybersecurity hacker attacks Wordfence WordPress Vulnerability

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-100781CVSS 9.6
    Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105293CVSS 9.2
    Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-100551CVSS 9.0
    OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105218CVSS 9.1
    gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider...
    📅 Updated: Oct 5, 2026
  • CVE-2026-82042CVSS 9.3
    UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access...
    📅 Updated: Oct 5, 2026
  • CVE-2026-79820CVSS 9.0
    A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
    📅 Updated: Oct 5, 2026
  • CVE-2026-105223CVSS 9.1
    maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data,...
    📅 Updated: Oct 5, 2026
  • CVE-2025-6544CVSS 9.8
    A deserialization vulnerability exists in h2oai/h2o-3 versions
    📅 Updated: Oct 5, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.