← back
CVE-2025-9321

WPCasa <= 1.4.1 - Unauthenticated Code Injection

CVSS 9.8 CRITICALEPSS 0.8%CWE-94
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
23 Sep 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input validation and restriction on the 'api_requests' function. This makes it possible for unauthenticated attackers to call arbitrary functions and execute code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
wpsight · WPCasa