Volver a los avisos de seguridad

WP Toolkit CVE-2026-47365

Argument injection vulnerability in WP Toolkit before version 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

Critical 9.9 CVSS
cPanel Plesk

CMD de actualización por defecto

cPanel: sudo /scripts/upcp --force  |  Plesk: plesk installer --select-release-current --update-installed

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel, Plesk software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel, Plesk under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

Argument injection vulnerability in WP Toolkit before version 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

Impact

Any cPanel server (on any Operating System) that has WP Toolkit installed with wp-toolkit version lower than version 6.11.0.

Call to Action

Update wp-toolkit to the fixed version 6.11.0 via the following command run as the root user:

# /usr/local/cpanel/3rdparty/wp-toolkit/bin/wp-toolkit-installer.sh –version 6.11.0

If the above command doesn’t work, please try:

# bash <(curl https://wp-toolkit.plesk.com/cPanel/installer.sh || wget -O – https://wp-toolkit.plesk.com/cPanel/installer.sh) –version 6.11.0

Preguntas frecuentes

What is CVE-2026-47365?
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
Is CVE-2026-47365 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 0.41% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-47365?
Update cPanel, Plesk to the patched release.Then confirm the running version matches the patched release listed above.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema