The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input validation and restriction on the 'api_requests' function. This makes it possible for unauthenticated attackers to call arbitrary functions and execute code.
We have discovered 356 live websites that are affected by CVE-2025-9321.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 356 live websites (92% of Wpcasa install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 14 versions ( 93% of all versions) |
| 110 websites | |
| 74 websites | |
| 34 websites | |
| 28 websites | |
| 20 websites | |
| 16 websites | |
| 8 websites | |
| 6 websites | |
| 6 websites | |
| 5 websites |
| .com | 121 websites |
| .com.au | 81 websites |
| .de | 48 websites |
| .it | 13 websites |
| .es | 13 websites |
| .ru | 7 websites |
| .net | 6 websites |
| .at | 5 websites |
| .ch | 3 websites |
| .eu | 3 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.***.au | **,*** | ||
| ***********.de | *,***,*** | ||
| *************.de | *,***,*** | ||
| *********.de | *,***,*** | ||
| ************.com | *,***,*** | ||
| **********.**.nz | *,***,*** | ||
| ********************.com | *,***,*** | ||
| ************************.de | *,***,*** | ||
| ***************.de | *,***,*** | ||
| *************.**.nz | *,***,*** |
FAQ