CVE-2026-87900: Critical severity Plesk WP Toolkit for cPanel vulnerability
Published Sep 23, 2026
·Updated
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Affected Software
1 affected component
Plesk WP Toolkit for cPanel<=6.11.2-10794
Event History
Sep 23, 2026
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations should be treated as affected?
Plesk WP Toolkit for cPanel versions 6.11.2-10794 and earlier should be treated as affected.
2
Does exploitation require prior access?
The issue is exploitable by remote authenticated users, so an attacker needs authenticated access.