CVE-2026-93699High· 8.5▾ TwilightArgument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87900Critical· 9.4Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
CVE-2026-93698Critical· 9.9Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
CVE-2026-93697Critical· 9.0There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
CVE-2026-93029Critical· 9.0There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
CVE-2026-87899Critical· 9.4Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
CVE-2026-87898Critical· 9.4OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.