Vendor
high
advisory
Security Updates for cPanel and WP Squared
2 CVEsWebPros has issued a security advisory addressing HTTP request smuggling and database privilege escalation vulnerabilities in cPanel and WP Squared products.
WP Squared +1
web-application-vulnerability
vulnerability-management
2c
high
advisory
Blind SQL Injection Vulnerability in Plesk XML-RPC API
1 rule 1 TTP 1 CVEA blind SQL injection vulnerability, tracked as CVE-2026-58046, affects the Plesk XML-RPC API, potentially allowing unauthenticated attackers to execute arbitrary database queries.
Plesk
web-application
sql-injection
vulnerability
1r
1t
1c
critical
advisory
WebPros cPanel & WHM and WP2 Authentication Bypass Vulnerability (CVE-2026-41940)
2 rules 1 TTP 1 CVECVE-2026-41940 is an authentication bypass vulnerability in WebPros cPanel & WHM and WP2 (WordPress Squared) that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
cPanel & WHM +1
cpanel
whm
wp2
wordpress
authentication-bypass
cve-2026-41940
initial-access
2r
1t
1c