Argument Injection Vulnerability in WP Toolkit for cPanel by cPanel
CVE-2026-87900

9.4CRITICAL

Key Information:

Vendor

Webpros

Vendor
CVE Published:
23 September 2026

Badges

📰 News Worthy

What is CVE-2026-87900?

The WP Toolkit for cPanel version 6.11.2-10794 and earlier is susceptible to an argument injection flaw. This vulnerability enables remote authenticated users to read arbitrary files and execute malicious code across different customer accounts. This can lead to significant security risks and unauthorized access to sensitive information, emphasizing the need for timely updates and mitigation strategies to protect against potential exploits.

Affected Version(s)

WP Toolkit for cPanel 0 <= 6.11.2-10794

WP Toolkit for cPanel 6.11.3-10850

News Articles

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

cPanel fixed three flaws, including one that lets any logged-in cPanel account run code as root and another that can modify other accounts' databases.

11 hours ago

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ali Mustafa (rz1027)
.