CVE-2026-93697: WebPros cPanel
Critical severity, CVSS 9.0. EPSS: 0.5% chance of exploitation in the next 30 days.
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
Affected products
- WebPros cPanel: before 11.138.0.11 (fixed in 11.138.0.11); before 11.136.0.45 (fixed in 11.136.0.45); before 11.134.0.61 (fixed in 11.134.0.61); before 11.110.0.148 (fixed in 11.110.0.148)
- WebPros Wp Squared: before 11.138.1.13 (fixed in 11.138.1.13)
Published 2026-10-02. Last modified 2026-10-02.