Known vulnerability record

CVE-2026-41940

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

Stable IDcve:CVE-2026-41940Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Keep the signals separate

CVSS severitycriticalScore 9.3 · source VulnCheck
EPSS probability97.9%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-04-30
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-04-29
CVE modified
2026-08-11
KEV date added
2026-04-30
Dataset fetched
2026-08-21T03:54:57.892Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.