CVE-2026-87900 — CVSS 9.4 CRITICAL

Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.

Loading application…