ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-41940

CRITICAL Export PDF

WebPros cPanel & WHM and WP2 (WordPress Squared) Vulnerability

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVSS Score
9.8
CRITICAL
Published
30 Apr 2026 00:00
Modified
N/A
Vendor
WebPros
Product
cPanel & WHM and WP2 (WordPress Squared)
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-306

Affected Systems

WebPros
cPanel & WHM and WP2 (WordPress Squared)
WebPros
CPanel & WHM And WP2 (WordPress Squared)

KEV Status

Known Exploited Vulnerability