logo

CVE-2026-47365: WordPress Toolkit Argument Injection in cPanel & WHM

ID: 4b190378-d206-5f15-b444-899680074ceb

STIX ID: report--4b190378-d206-5f15-b444-899680074ceb

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

...
...

A critical argument-injection and authorization-bypass vulnerability (CVE-2026-47365, CVSS 9.9) in WordPress Toolkit versions prior to 6.11.0 on cPanel & WHM allows low-privileged authenticated hosting tenants to execute wp-toolkit CLI commands in the context of other accounts, enabling cross-tenant data exposure and account takeover; administrators should upgrade to 6.11.0+ immediately and audit for suspicious cross-account activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.