Argument Injection in WP Toolkit for cPanel Affects Server Security
CVE-2026-93699

8.5HIGH

Key Information:

Vendor

Webpros

Vendor
CVE Published:
8 October 2026

What is CVE-2026-93699?

The WP Toolkit for cPanel is susceptible to an argument injection vulnerability that permits local users to execute arbitrary code under the context of other accounts hosted on the same server. This could lead to unauthorized access or manipulation of data by leveraging this security flaw, exposing affected systems to significant risks. It is crucial for administrators to assess their installations and apply necessary security measures to mitigate potential exploitation.

Affected Version(s)

WP Toolkit 0 < 6.11.4

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rz1027 (rz1027)
.