August 3, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-5821NVD

Vulnerability Summary

The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly logging in a user with the data that was previously verified through the facebook_ajax_login_callback() function. This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site which can easily be created by default through the temp user functionality, and access to the administrative user's email.
Severity Level
CRITICAL(9.8)
Published Date
Aug 23, 2025
Last Modified
Apr 8, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.44%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh