CVE-2026-93699: WebPros Wp Toolkit

High severity, CVSS 8.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.

Affected products

  • WebPros Wp Toolkit: before 6.11.4 (fixed in 6.11.4)

Published 2026-10-08. Last modified 2026-10-08.