Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93699 2 Webpros, Wordpress-extensions 2 Wordpress-toolkit, Wp Toolkit 2026-10-09 N/A
Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.
CVE-2026-47365 2 Webpros, Wordpress 2 Wordpress-toolkit, Wordpress 2026-06-12 9.9 Critical
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.