Junglewise Threat Intelligence

CVE-2026-87900: Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute a

CVE-2026-87900 · Severity: info · Published 2026-09-23

Executive brief

Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.