CVE-2026-93699
Received Received - Intake

Argument Injection in WP Toolkit for cPanel

Vulnerability report for CVE-2026-93699, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: HackerOne

Description

Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
WebPros WP Toolkit 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an argument injection flaw in WP Toolkit for cPanel. It allows local users on a server to inject malicious arguments into commands, enabling them to execute arbitrary code as other user accounts on the same server.

Detection Guidance

Check the installed version of WP Toolkit by running: rpm -qa | grep wp-toolkit. If the version is v6.11.3 or older, the system is vulnerable.

Impact Analysis

If exploited, this vulnerability could allow an attacker with local access to run arbitrary code as another user on the server. This could lead to unauthorized access to sensitive data, privilege escalation, or further compromise of the server.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations must patch this flaw to maintain compliance and protect user data.

Mitigation Strategies

Update WP Toolkit to version v6.11.4 or later by running: bash <(curl https://wp-toolkit.plesk.com/cPanel/installer.sh || wget -O - https://wp-toolkit.plesk.com/cPanel/installer.sh ) --version 6.11.4.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93699. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart