Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-87900: WP Toolkit for cPanel allows logged‑in users to read files

CVE-2026-87900 · published 16 days ago
Summary

If someone signs into cPanel with a valid account, they can use the WP Toolkit to open any file on the server and even run their own code. This can expose sensitive data across all customers hosted on that machine. Upgrade WP Toolkit for cPanel to the latest version or apply the vendor's patch and restrict account access to trusted users.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
webpros wp toolkit for cpanel <= 6.11.2-10794
Original advisory text
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-87900 · MITRE
Track software like this
Free during beta