CVE-2025-62043: Wpsight Wpcasa

Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa allows DOM-Based XSS.This issue affects WPCasa: from n/a through 1.4.1.

Affected products

  • Wpsight Wpcasa: up to and including 1.4.1

Published 2026-03-19. Last modified 2026-06-17.