CVE-2026-41940 CRITICAL

WebPros cPanel & WHM and WP2 (WordPress Squared) Vulnerability
Generated: 10 Oct 2026 19:57 • CVE Threat Intelligence

Description

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

9.8
CVSS CRITICAL

Details

Published
30 Apr 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
WebPros
Product
cPanel & WHM and WP2 (WordPress Squared)
Fix Version
Vendor Patch / Mitigation Available