WebPros WP Squared

4 known vulnerabilities in WebPros WP Squared, 4 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-41940 CVSS 9.3 critical · actively exploited WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

Latest vulnerabilities

  • CVE-2026-93698 CVSS 9.9 critical Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
  • CVE-2026-93697 CVSS 9.0 critical There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
  • CVE-2026-93029 CVSS 9.0 critical There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
  • CVE-2026-41940 CVSS 9.3 critical · actively exploited WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability