Security: LiteSpeed plugin automatically removed during nightly update – May 19, 2026
A security vulnerability was found in the plugin provided by LiteSpeed that allowed unauthorized root access to the server.
Default Update CMD
sudo /scripts/upcp --force
Situation
A security vulnerability was found in the plugin provided by LiteSpeed that allowed unauthorized root access to the server.
Impact
In order to mitigate this vulnerability further, it is recommended to disable the LiteSpeed User-End Plugin for cPanel. This plugin will be automatically removed as part of the cPanel update on May 19, 2026, for all cPanel versions.
Note: The LiteSpeed web service will continue to function without issue.
Call to Action
The LiteSpeed plugin will be automatically disabled as part of the cPanel update process. Run the following to ensure that cPanel is fully up-to-date:
# /scripts/upcp –force
To immediately process the plugin removal, the following command should be run:
# /usr/local/lsws/admin/misc/lscmctl cpanelplugin –uninstall
Additional Information
Security: SEC-73728 cPanel & WHM / WP2 Security Update – May 19, 2026
Security: SEC-73755 cPanel & WHM / WP2 Security Update – May 19, 2026
How to Apply the Fix
Update the affected packages on your server to the patched release, then restart the relevant services.
sudo /scripts/upcp --force
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System