CVE-2026-47365: WordPress Toolkit Argument Injection in cPanel & WHM
ID: 4b190378-d206-5f15-b444-899680074ceb
STIX ID: report--4b190378-d206-5f15-b444-899680074ceb
Feed Name: CosmicBytez Labs
Threat Score
A critical argument-injection and authorization-bypass vulnerability (CVE-2026-47365, CVSS 9.9) in WordPress Toolkit versions prior to 6.11.0 on cPanel & WHM allows low-privileged authenticated hosting tenants to execute wp-toolkit CLI commands in the context of other accounts, enabling cross-tenant data exposure and account takeover; administrators should upgrade to 6.11.0+ immediately and audit for suspicious cross-account activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
