Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-87900: WP Toolkit for cPanel allows logged‑in users to read files
CVE-2026-87900 · published 16 days ago
Summary
If someone signs into cPanel with a valid account, they can use the WP Toolkit to open any file on the server and even run their own code. This can expose sensitive data across all customers hosted on that machine. Upgrade WP Toolkit for cPanel to the latest version or apply the vendor's patch and restrict account access to trusted users.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| webpros | wp toolkit for cpanel | <= 6.11.2-10794 |
Original advisory text
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta