
wpCAS Security & Risk Analysis
wordpress.org/plugins/wpcaswpCAS integrates WordPress into an established CAS architecture, allowing centralized management and authentication of user credentials in a heterogen …
Is wpCAS Safe to Use in 2026?
Use With Caution
Score 63/100wpCAS has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wpcas plugin v1.07 exhibits a mixed security posture. While the static analysis shows no direct attack surface (AJAX handlers, REST API routes, shortcodes, cron events) and all SQL queries utilize prepared statements, significant concerns arise from the output escaping and vulnerability history. The low percentage of properly escaped output (18%) indicates a strong potential for Cross-Site Scripting (XSS) vulnerabilities, even if not directly flagged by the taint analysis. The presence of a known medium severity Cross-Site Scripting (XSS) vulnerability, which remains unpatched and was discovered in 2026, is a critical indicator of ongoing risk. The fact that this is the only known CVE also suggests a potential for undiscovered vulnerabilities. The absence of nonce and capability checks across the board, coupled with a low output escaping rate, amplifies the risk associated with any potential input vectors that might exist but were not identified by the static analysis.
Key Concerns
- Unpatched medium severity CVE
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
- Flows with unsanitized paths
wpCAS Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
wpCAS <= 1.07 - Reflected Cross-Site Scripting
wpCAS Code Analysis
Output Escaping
Data Flow Analysis
wpCAS Attack Surface
WordPress Hooks 10
Maintenance & Trust
wpCAS Maintenance & Trust
Maintenance Signals
Community Trust
wpCAS Alternatives
wpCAS Server
wpcas-server
Turns WordPress or WordPress MU into a CAS single sign-on authenticator.
WP Cassify
wp-cassify
The plugin is an Apereo CAS Client. It performs CAS authentication and autorization for Wordpress.
Cassava CAS Server
wp-cas-server
Cassava provides authentication services based on the Jasig CAS protocol.
Authorizer
authorizer
Authorizer limits login attempts, restricts access to specific users, and authenticates against external sources (OAuth2, Google, LDAP, or CAS).
WPCasa Contact Form 7
wpcasa-contact-form-7
Add support for Contact Form 7 to attach property details to the contact email sent from WPCasa listing pages.
wpCAS Developer Profile
7 plugins · 290 total installs
How We Detect wpCAS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.