CVE-2026-47365: Critical severity Cpanel WordPress Toolkit vulnerability
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Toolkit (cPanel & WHM)to a version that resolves this vulnerability.Fixed in 6.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47365?
The severity of CVE-2026-47365 is critical with a CVSS score of 9.9.
How do I fix CVE-2026-47365?
To fix CVE-2026-47365, update the WordPress Toolkit to version 6.11.0 or later.
What is the impact of CVE-2026-47365?
CVE-2026-47365 allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands.
Who is affected by CVE-2026-47365?
CVE-2026-47365 affects users of WordPress Toolkit versions prior to 6.11.0 as used in cPanel & WHM.
What type of vulnerability is CVE-2026-47365?
CVE-2026-47365 is an argument injection vulnerability.