{"id":"CVE-2026-93697","title":"There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.","summary":"There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.","severity":"critical","cvss":9,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-79"],"vendor":"Webpros","product":"cPanel","affected":["cPanel < 11.138.0.11","cPanel < 11.136.0.45","cPanel < 11.134.0.61","cPanel < 11.110.0.148","wp_squared < 11.138.1.13"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T07:16:38.893","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93697","references":[{"url":"https://docs.cpanel.net/changelogs/110-change-log/#1100148","label":"support@hackerone.com"},{"url":"https://docs.cpanel.net/changelogs/134-change-log/#134061","label":"support@hackerone.com"},{"url":"https://docs.cpanel.net/changelogs/136-change-log/#136045","label":"support@hackerone.com"},{"url":"https://docs.cpanel.net/changelogs/138-change-log/#138011","label":"support@hackerone.com"},{"url":"https://docs.wpsquared.com/changelogs/versions/changelog/#138113","label":"support@hackerone.com"},{"url":"https://hackerone.com/reports/4047787","label":"support@hackerone.com"},{"url":"https://support.cpanel.net/hc/en-us/articles/43845930445207-Security-CVE-2026-93697-Stored-XSS-in-WHM-s-Account-Modification-Interfaces-September-29-2026","label":"support@hackerone.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T07:13:06.674Z","slug":"CVE-2026-93697","body":"## Overview\n\nThere is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":49.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}