WebPros WP Squared
4 known vulnerabilities in WebPros WP Squared, 4 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-41940 CVSS 9.3 critical · actively exploited WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Latest vulnerabilities
- CVE-2026-93698 CVSS 9.9 critical Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
- CVE-2026-93697 CVSS 9.0 critical There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
- CVE-2026-93029 CVSS 9.0 critical There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
- CVE-2026-41940 CVSS 9.3 critical · actively exploited WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability