Argument Injection in WP Toolkit for cPanel Allows Cross-Account File Read and RCE
AI analysis
CVE-2026-87900 is an argument injection flaw (CWE-88) in the WP Toolkit add-on for cPanel servers, affecting version 6.11.2-10794 and earlier. A remote attacker needs only a low-privileged, authenticated hosting account on an affected server and sends specially crafted arguments to WP Toolkit operations, with no user interaction required. Successful exploitation lets the attacker read arbitrary files and execute arbitrary code across other customer accounts on the same server, and press reports indicate the issue can escalate to running code as root and taking full control of the hosting server. The affected population is hosting providers running cPanel with WP Toolkit installed, along with all of their hosted customers. The flaw is rated critical (CVSS 4.0: 9.4), but it is not on the CISA KEV list, no public proof of concept exists, and no exploitation in the wild has been reported so far.
What to do: Hosting providers should immediately update WP Toolkit for cPanel to any build newer than 6.11.2-10794 via WHM and verify the installed version. Because exploitation only requires an ordinary authenticated hosting account, review server logs for unusual WP Toolkit activity, cross-account file access, or unexpected processes/cron jobs, and rotate credentials if compromise is suspected. Customers on shared hosts that have not patched should treat files and credentials in their accounts as potentially exposed until the provider confirms remediation.
Affected
| Plesk / WebPros (WP Toolkit) WP Toolkit for cPanel | 6.11.2-10794 and earlier |
Estimated exposure
massRoughly hundreds of thousands of servers and millions of hosted customer sites (order-of-magnitude estimate; exact count unknown) — Public internet scans have long shown on the order of a million or more cPanel-based hosts, and WP Toolkit is a widely adopted commercial add-on on cPanel servers, so a substantial fraction of that base is plausibly affected; each affected…