WebPros cPanel & WHM and WP2 (WordPress Squared) Vulnerability
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CVSS Score
9.8
CRITICAL
Published
30 Apr 2026 00:00
Modified
N/A
Vendor
WebPros
Product
cPanel & WHM and WP2 (WordPress Squared)
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-306
Affected Systems
WebPros
cPanel & WHM and WP2 (WordPress Squared)
WebPros
CPanel & WHM And WP2 (WordPress Squared)
External Links
KEV Status
Known Exploited Vulnerability