Known vulnerability record
CVE-2026-41940
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Summary
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Signals
Keep the signals separate
CVSS severitycriticalScore 9.3 · source VulnCheck
EPSS probability97.9%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-04-30
Ransomware useknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2026-04-29
- CVE modified
- 2026-08-11
- KEV date added
- 2026-04-30
- Dataset fetched
- 2026-08-21T03:54:57.892Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2026-41940 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2026-41940 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.