Description
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
Published: 2026-10-02
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Stored XSS
Action: Immediate Patch
AI Analysis

Impact

A stored cross‑site scripting vulnerability was discovered in the Manage SSL Hosts interface of WHM. An attacker who can submit a malicious payload through this interface can have the script stored and later executed in the browser context of any user who visits the page. The stored code can perform actions as the victim, leading to arbitrary code execution and full compromise of the affected server.

Affected Systems

The flaw affects installations of the WHM administration tool from cPanel and the WP Squared product suite offered by Webpros. No specific version ranges were disclosed in the advisory, so any installation using the Manage SSL Hosts page is potentially vulnerable until a patch is applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 9, indicating high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is an attacker who can inject content into the Manage SSL Hosts form, which is inferred from the description to require valid WHM credentials or the ability to trick an injected, the payload is executed views the page, immediately granting attacker‑controlled code execution.

Generated by OpenCVE AI on October 2, 2026 at 08:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security updates for cPanel and WP Squared that contain the fixed Manage SSL Hosts code.
  • Verify that the WHM interface is only accessible from trusted, isolated networks or via VPN and restrict administrative access to privileged users.
  • As a temporary preventive measure, disable or restrict the SSL Hosts management feature if a patch is not yet available.

Generated by OpenCVE AI on October 2, 2026 at 08:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros cpanel
Webpros wp Squared
Vendors & Products Webpros
Webpros cpanel
Webpros wp Squared

Fri, 02 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Title Stored XSS in WHM Manage SSL Hosts Allows Remote Code Execution

Fri, 02 Oct 2026 06:45:00 +0000


Subscriptions

Webpros Cpanel Wp Squared
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-10-02T18:12:44.517Z

Reserved: 2026-09-17T15:00:00.689Z

Link: CVE-2026-93029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T07:16:38.733

Modified: 2026-10-02T18:47:49.947

Link: CVE-2026-93029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:30:23Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')