{"id":"CVE-2026-87900","published":"2026-09-23T20:17:20.613","lastModified":"2026-09-24T21:16:28.120","description":"Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-88"],"vendors":[],"products":[],"references":[{"url":"https://support.cpanel.net/hc/en-us/articles/43597969409943","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}