CVE-2026-93697
published 2026-10-02CVE-2026-93697: There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
PriorityP346critical9CVSS 3.0
AVNACLPRLUIRSCCHIHAH
EPSS
0.40%
32.1th percentile
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| webpros | cpanel | < 11.138.0.11 | 11.138.0.11 |
| webpros | cpanel | < 11.136.0.45 | 11.136.0.45 |
| webpros | cpanel | < 11.134.0.61 | 11.134.0.61 |
| webpros | cpanel | < 11.110.0.148 | 11.110.0.148 |
| webpros | wp_squared | < 11.138.1.13 | 11.138.1.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
https://docs.cpanel.net/changelogs/110-change-log/#1100148https://docs.cpanel.net/changelogs/134-change-log/#134061https://docs.cpanel.net/changelogs/136-change-log/#136045https://docs.cpanel.net/changelogs/138-change-log/#138011https://docs.wpsquared.com/changelogs/versions/changelog/#138113https://hackerone.com/reports/4047787https://support.cpanel.net/hc/en-us/articles/43845930445207-Security-CVE-2026-93697-Stored-XSS-in-WHM-s-Account-Modification-Interfaces-September-29-2026
2026-10-02
Published