WP Toolkit cross-account database modification security flaw (CVE-2026-87900)
Vulnerability
Summary
Hide ▲
Show ▼
The WP Toolkit flaw CVE-2026-87900 lets a logged-in cPanel user change databases in other accounts, creating cross-account data-integrity risk on shared hosting systems. cPanel fixed the issue in WP Toolkit 6.11.3 or later while 6.11.2-10794 and older remain affected.
Related Happenings
CPanel CalDAV and CardDAV calendar/contact read flaw (CVE-2026-68490)
Vulnerability
H score27
First: 23.09.2026 15:16
Last: 23.09.2026 15:16
Sources 1
How related:
That third flaw lets a local user on the server read other accounts' calendar events and contacts, but not change them or gain root access.
About this happening:
cPanel fixed CVE-2026-68490, a CalDAV and CardDAV flaw that lets a local user read other accounts' calendar events and contacts on affected hosting systems. The bu...
CPanel CalDAV and CardDAV calendar/contact read flaw (CVE-2026-68490)
VulnerabilityHow related: That third flaw lets a local user on the server read other accounts' calendar events and contacts, but not change them or gain root access.
About this happening: cPanel fixed CVE-2026-68490, a CalDAV and CardDAV flaw that lets a local user read other accounts' calendar events and contacts on affected hosting systems. The bu...
CPanel CalDAV and CardDAV root code execution security flaw (CVE-2026-87899)
Vulnerability
H score33
First: 23.09.2026 15:16
Last: 23.09.2026 15:16
Sources 1
How related:
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.
About this happening:
cPanel's fix for CVE-2026-87899 closes a CalDAV and CardDAV flaw that let a logged-in hosting account run code as root, putting affected servers at risk of full cont...
CPanel CalDAV and CardDAV root code execution security flaw (CVE-2026-87899)
VulnerabilityHow related: A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.
About this happening: cPanel's fix for CVE-2026-87899 closes a CalDAV and CardDAV flaw that let a logged-in hosting account run code as root, putting affected servers at risk of full cont...
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/Mitigation
H score38
First: 16.06.2026 08:41
Last: 16.06.2026 08:41
Sources 1
About this happening:
CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/MitigationAbout this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
CPanel CVE-2026-41940 mitigation guidance
Advisory/Mitigation
H score89
First: 30.04.2026 14:40
Last: 30.04.2026 14:40
Sources 1
About this happening:
cPanel issued mitigation guidance for CVE-2026-41940 after fixes became available for cPanel, WHM, and WP Squared, urging customers to restart cpsrvd to reduce exposur...
CPanel CVE-2026-41940 mitigation guidance
Advisory/MitigationAbout this happening: cPanel issued mitigation guidance for CVE-2026-41940 after fixes became available for cPanel, WHM, and WP Squared, urging customers to restart cpsrvd to reduce exposur...
Timeline
-
23.09.2026 15:16 2 articles · 2h ago
WP Toolkit lets a cPanel user change other accounts' databases
Initial DisclosurecPanel said on September 22, 2026 that the WP Toolkit plugin used to install and manage WordPress sites allows a logged-in cPanel user to change databases that belong to other accounts, creating cross-account database modification risk on shared hosting systems. cPanel also released WP Toolkit 6.11.3 or later to fix CVE-2026-87900.
Show sources
- New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control — thehackernews.com — 23.09.2026 15:16
- New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control — thehackernews.com — 23.09.2026 15:16