CVE-2025-9321: WPCasa <= 1.4.1 - Unauthenticated Code Injection
Published Sep 23, 2025
·Updated
The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input validation and restriction on the 'apirequests' function. This makes it possible for unauthenticated attackers to call arbitrary functions and execute code.
Affected Software
1 affected component
WPCasa WPCasa<=1.4.1
Event History
Sep 23, 2025
CVE Published
via MITRE·04:26 AM
Data Sourced
via MITRE·04:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Feb 28, 57989
Event
via FIRST·06:49 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9321?
CVE-2025-9321 is classified as a critical vulnerability due to its potential for code injection.
2
How do I fix CVE-2025-9321?
To fix CVE-2025-9321, update the WPCasa plugin to version 1.4.2 or later.
3
What is the impact of CVE-2025-9321?
The impact of CVE-2025-9321 allows unauthenticated attackers to execute arbitrary functions on the affected WordPress site.
4
Which versions are affected by CVE-2025-9321?
CVE-2025-9321 affects all versions of the WPCasa plugin up to and including version 1.4.1.
5
Is authentication required to exploit CVE-2025-9321?
No, CVE-2025-9321 can be exploited by unauthenticated attackers.