CVE-2026-87900: WebPros Wp Toolkit For cPanel

Critical severity, CVSS 9.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.

Affected products

  • WebPros Wp Toolkit For cPanel: up to and including 6.11.2-10794

Published 2026-09-23. Last modified 2026-09-24.