CVE-2026-29202: WebPros cPanel
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
Affected products
- WebPros cPanel: from 11.136.0.0, before 11.136.0.9 (fixed in 11.136.0.9); from 11.134.0.0, before 11.134.0.25 (fixed in 11.134.0.25); from 11.132.0.0, before 11.132.0.31 (fixed in 11.132.0.31); from 11.130.0.0, before 11.130.0.22 (fixed in 11.130.0.22); from 11.126.0.0, before 11.126.0.58 (fixed in 11.126.0.58); from 11.124.0.0, before 11.124.0.37 (fixed in 11.124.0.37); …
- WebPros cPanel Cloudlinux 6, Centos 6: from 11.110.0.0, before 11.110.0.116 (fixed in 11.110.0.116)
- WebPros Wp Squared: from 11.136.1.0, before 11.136.1.11 (fixed in 11.136.1.11)
Published 2026-05-08. Last modified 2026-06-17.