CVE-2026-47365
9.9CRITICAL
What is CVE-2026-47365?
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
Affected Version(s)
WordPress-Toolkit 0 < 6.11.0