CVE-2026-93029
published 2026-10-02CVE-2026-93029: There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
PriorityP347critical9CVSS 3.0
AVNACLPRLUIRSCCHIHAH
EPSS
0.40%
32.1th percentile
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| webpros | cpanel | < 11.138.0.11 | 11.138.0.11 |
| webpros | cpanel | < 11.136.0.45 | 11.136.0.45 |
| webpros | cpanel | < 11.134.0.61 | 11.134.0.61 |
| webpros | cpanel | < 11.110.0.148 | 11.110.0.148 |
| webpros | wp_squared | < 11.138.1.13 | 11.138.1.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
https://docs.cpanel.net/changelogs/110-change-log/#1100148https://docs.cpanel.net/changelogs/134-change-log/#134061https://docs.cpanel.net/changelogs/136-change-log/#136045https://docs.cpanel.net/changelogs/138-change-log/#138011https://docs.wpsquared.com/changelogs/versions/changelog/#138113https://hackerone.com/reports/4047106https://support.cpanel.net/hc/en-us/articles/43845929235351-Security-CVE-2026-93029-Stored-XSS-in-WHM-s-Manage-SSL-Hosts-Interface-September-29-2026
2026-10-02
Published