CVE-2026-87900EPSS p47.6%

CVE-2026-87900CVE-2026-87900

Description

Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.

Scoring

EPSS0.61% probability of exploitation · percentile 47.6% · 2026-10-05T12:00:23Z
Last modified2026-09-24
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.