Junglewise Threat Intelligence

CVE-2025-5804: Case Themes Case Theme User Local File Inclusion

CVE-2025-5804 · Severity: high · CVSS 7.5 · Published 2026-04-10

Executive brief

The Case Theme User plugin for WordPress is vulnerable to a security flaw that allows attackers to access sensitive files on the web server. By tricking a user into clicking a malicious link or visiting a specific page, an attacker could potentially steal database credentials or other private configuration data. This could lead to a full takeover of the website's database and compromise of customer information.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Case Themes Case Theme User plugin for WordPress due to improper control of filenames in include/require statements (CWE-98). The vulnerability allows an unauthenticated attacker to include local files from the server, which could result in the disclosure of sensitive information such as wp-config.php. Exploitation requires user interaction, such as a privileged user clicking a malicious link or visiting a crafted page (AC:H/UI:R). The issue affects all versions prior to 1.0.4, and users are advised to upgrade to version 1.0.4 or later to remediate the flaw.

Affected products

  • Case Themes Case Theme User < 1.0.4

Timeline

  • 2025-05-31: other: Vulnerability reported by researcher Bonds
  • 2025-07-01: advisory: Patchstack published advisory and mitigation rules
  • 2026-04-10: disclosed: CVE published to NVD

References