WP Toolkit for cPanel 6.11.2-10794 及更早版本存在参数注入漏洞,允许远程经过身份验证的用户读取任意文件,并跨客户账户执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WebPros | WP Toolkit for cPanel | 0 ~ 6.11.2-10794 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87899 | 9.4 CRITICAL | cPanel提权漏洞:远程用户可获Root权限执行代码 |
| CVE-2026-87898 | 9.4 CRITICAL | Plesk远程认证命令注入漏洞 |
| CVE-2026-68492 | 8.7 HIGH | Plesk 18.0.34-18.0.81 路径遍历漏洞 |
| CVE-2026-68490 | 8.2 HIGH | Thunderbird 权限配置错误致敏感信息泄露 |
No comments yet