CVE-2025-9321

WPCasa <= 1.4.1 - Unauthenticated Code Injection

The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input validation and restriction on the 'api_requests' function. This makes it possible for unauthenticated attackers to call arbitrary functions and execute code.


We have discovered 356 live websites that are affected by CVE-2025-9321.

Run a Free Instant Scan




Affected Software

Product  Wpcasa
Category Wordpress Plugins
Vulnerable Domains356 live websites (92% of Wpcasa install base)
Vulnerable Versions
  • from 0 through 1.4.1
Vulnerable Versions Count14 versions ( 93% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Sep 23, 2025
  • Updated - Sep 23, 2025

Credits

  • Michael Mazzolini (finder)

Website Distribution by Country

Number of websites using CVE-2025-9321
United States110 websites



Germany74 websites
Spain34 websites
Australia28 websites
Italy20 websites
France16 websites
Russia8 websites
GB6 websites
New Zealand6 websites
Cyprus5 websites

Website Distribution by TLD

Number of websites using CVE-2025-9321
.com121 websites
.com.au81 websites
.de48 websites
.it13 websites
.es13 websites
.ru7 websites
.net6 websites
.at5 websites
.ch3 websites
.eu3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-9321

Top websites that are affected by CVE-2025-9321. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.***.au Australia**,***
***********.de Germany*,***,***
*************.de Germany*,***,***
*********.de Germany*,***,***
************.com Italy*,***,***
**********.**.nz New Zealand*,***,***
********************.com United States*,***,***
************************.de Germany*,***,***
***************.de Germany*,***,***
*************.**.nz New Zealand*,***,***
See full domain list

FAQ

CVE-2025-9321 is Improper Control of Generation of Code ('Code Injection') in Wpcasa
A total of 356 websites have been identified as vulnerable to CVE-2025-9321, based on global website indexing conducted by WebTechSurvey.
The Wpcasa is affected by the CVE-2025-9321 vulnerability.
Wpcasa versions up to and including 1.4.1 are vulnerable to CVE-2025-9321.