Back to Security Advisories

WP Toolkit CVE-2026-47365

Argument injection vulnerability in WP Toolkit before version 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

Critical 9.9 CVSS
cPanel Plesk

Default Update CMD

cPanel: sudo /scripts/upcp --force  |  Plesk: plesk installer --select-release-current --update-installed

What this means under a SharedLicense license

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel, Plesk software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel, Plesk under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

Argument injection vulnerability in WP Toolkit before version 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

Impact

Any cPanel server (on any Operating System) that has WP Toolkit installed with wp-toolkit version lower than version 6.11.0.

Call to Action

Update wp-toolkit to the fixed version 6.11.0 via the following command run as the root user:

# /usr/local/cpanel/3rdparty/wp-toolkit/bin/wp-toolkit-installer.sh –version 6.11.0

If the above command doesn’t work, please try:

# bash <(curl https://wp-toolkit.plesk.com/cPanel/installer.sh || wget -O – https://wp-toolkit.plesk.com/cPanel/installer.sh) –version 6.11.0

Frequently Asked Questions

What is CVE-2026-47365?
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
Is CVE-2026-47365 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 0.41% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-47365?
Update cPanel, Plesk to the patched release.Then confirm the running version matches the patched release listed above.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System