CVE-2026-41940
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Severity Score
9.3
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
Act
*SSVC
Descriptions
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Act
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2026-04-22 CVE Reserved
- 2026-04-29 CVE Published
- 2026-04-30 Exploited in Wild
- 2026-05-03 KEV Due Date
- 2026-05-04 First Exploit
- 2026-05-06 CVE Updated
- 2026-05-13 EPSS Updated
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (9)
| URL | Date | SRC |
|---|---|---|
| https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 | 2026-05-04 |
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | >= 11.40 < 86.0.41 Search vendor "Cpanel" for product "Cpanel" and version " >= 11.40 < 86.0.41" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | >= 88.0.0 < 110.0.97 Search vendor "Cpanel" for product "Cpanel" and version " >= 88.0.0 < 110.0.97" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | >= 112.0.0 < 118.0.63 Search vendor "Cpanel" for product "Cpanel" and version " >= 112.0.0 < 118.0.63" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | >= 120.0.0 < 124.0.35 Search vendor "Cpanel" for product "Cpanel" and version " >= 120.0.0 < 124.0.35" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | >= 126.0.1 < 126.0.54 Search vendor "Cpanel" for product "Cpanel" and version " >= 126.0.1 < 126.0.54" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | >= 128.0.0 < 130.0.19 Search vendor "Cpanel" for product "Cpanel" and version " >= 128.0.0 < 130.0.19" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | >= 132.0.0 < 132.0.29 Search vendor "Cpanel" for product "Cpanel" and version " >= 132.0.0 < 132.0.29" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | >= 134.0.0 < 134.0.20 Search vendor "Cpanel" for product "Cpanel" and version " >= 134.0.0 < 134.0.20" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | >= 136.0.0 < 136.0.5 Search vendor "Cpanel" for product "Cpanel" and version " >= 136.0.0 < 136.0.5" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Whm Search vendor "Cpanel" for product "Whm" | >= 11.40 < 86.0.41 Search vendor "Cpanel" for product "Whm" and version " >= 11.40 < 86.0.41" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Whm Search vendor "Cpanel" for product "Whm" | >= 88.0.0 < 110.0.97 Search vendor "Cpanel" for product "Whm" and version " >= 88.0.0 < 110.0.97" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Whm Search vendor "Cpanel" for product "Whm" | >= 112.0.0 < 118.0.63 Search vendor "Cpanel" for product "Whm" and version " >= 112.0.0 < 118.0.63" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Whm Search vendor "Cpanel" for product "Whm" | >= 120.0.0 < 124.0.35 Search vendor "Cpanel" for product "Whm" and version " >= 120.0.0 < 124.0.35" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Whm Search vendor "Cpanel" for product "Whm" | >= 126.0.1 < 126.0.54 Search vendor "Cpanel" for product "Whm" and version " >= 126.0.1 < 126.0.54" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Whm Search vendor "Cpanel" for product "Whm" | >= 128.0.0 < 130.0.19 Search vendor "Cpanel" for product "Whm" and version " >= 128.0.0 < 130.0.19" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Whm Search vendor "Cpanel" for product "Whm" | >= 132.0.0 < 132.0.29 Search vendor "Cpanel" for product "Whm" and version " >= 132.0.0 < 132.0.29" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Whm Search vendor "Cpanel" for product "Whm" | >= 134.0.0 < 134.0.20 Search vendor "Cpanel" for product "Whm" and version " >= 134.0.0 < 134.0.20" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Whm Search vendor "Cpanel" for product "Whm" | >= 136.0.0 < 136.0.5 Search vendor "Cpanel" for product "Whm" and version " >= 136.0.0 < 136.0.5" | - |
Affected
| ||||||
| Cpanel Search vendor "Cpanel" | Wp Squared Search vendor "Cpanel" for product "Wp Squared" | < 136.1.7 Search vendor "Cpanel" for product "Wp Squared" and version " < 136.1.7" | wordpress |
Affected
| ||||||
