Find notable cyber news and cases, enriched with sources, timelines, and signals.

WP Toolkit cross-account database modification security flaw (CVE-2026-87900)

Vulnerability
First reported
Last updated
Happening score
H score 1
1 unique sources, 1 articles

Summary

Hide ▲

The WP Toolkit flaw CVE-2026-87900 lets a logged-in cPanel user change databases in other accounts, creating cross-account data-integrity risk on shared hosting systems. cPanel fixed the issue in WP Toolkit 6.11.3 or later while 6.11.2-10794 and older remain affected.

Related Happenings

CPanel CalDAV and CardDAV calendar/contact read flaw (CVE-2026-68490)

Vulnerability
H score27 First: 23.09.2026 15:16 Last: 23.09.2026 15:16 Sources 1

How related: That third flaw lets a local user on the server read other accounts' calendar events and contacts, but not change them or gain root access.

About this happening: cPanel fixed CVE-2026-68490, a CalDAV and CardDAV flaw that lets a local user read other accounts' calendar events and contacts on affected hosting systems. The bu...

CPanel CalDAV and CardDAV root code execution security flaw (CVE-2026-87899)

Vulnerability
H score33 First: 23.09.2026 15:16 Last: 23.09.2026 15:16 Sources 1

How related: A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.

About this happening: cPanel's fix for CVE-2026-87899 closes a CalDAV and CardDAV flaw that let a logged-in hosting account run code as root, putting affected servers at risk of full cont...

CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)

Advisory/Mitigation
H score38 First: 16.06.2026 08:41 Last: 16.06.2026 08:41 Sources 1

About this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...

CPanel CVE-2026-41940 mitigation guidance

Advisory/Mitigation
H score89 First: 30.04.2026 14:40 Last: 30.04.2026 14:40 Sources 1

About this happening: cPanel issued mitigation guidance for CVE-2026-41940 after fixes became available for cPanel, WHM, and WP Squared, urging customers to restart cpsrvd to reduce exposur...

Timeline

  1. 23.09.2026 15:16 2 articles · 2h ago

    WP Toolkit lets a cPanel user change other accounts' databases

    Initial Disclosure

    cPanel said on September 22, 2026 that the WP Toolkit plugin used to install and manage WordPress sites allows a logged-in cPanel user to change databases that belong to other accounts, creating cross-account database modification risk on shared hosting systems. cPanel also released WP Toolkit 6.11.3 or later to fix CVE-2026-87900.

    Show sources