Junglewise Threat Intelligence

CVE-2026-47365: cPanel WordPress Toolkit argument injection in CLI commands

CVE-2026-47365 · Severity: critical · CVSS 9.9 · Published 2026-06-12

Vendors: cPanel.

Executive brief

A security vulnerability exists in the WordPress Toolkit used by cPanel and WHM hosting platforms. This flaw allows a user with a standard account on a shared server to bypass security boundaries and run administrative commands as if they were another user. This could lead to unauthorized access to other customers' websites, data theft, or full site compromise.

Technical details

This vulnerability is classified as an argument injection (CWE-88) within the WordPress Toolkit component of cPanel & WHM. The flaw stems from improper neutralization of argument delimiters, which allows a remote authenticated user with low privileges to inject additional parameters into CLI commands. By exploiting this, an attacker can bypass cross-tenant isolation mechanisms and execute arbitrary 'wp-toolkit' commands with the permissions of a different account. This can lead to a complete compromise of other WordPress installations on the same server. The issue is resolved in WordPress Toolkit version 6.11.0.

Affected products

  • cPanel WordPress Toolkit before 6.11.0
  • cPanel WHM before 6.11.0

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References