Description
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
Published: 2026-10-02
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: Stored Cross Site Scripting with arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that allows an attacker to embed malicious code into the WHM Mass Modify Accounts interface, potentially executing arbitrary code on the server. The flaw arises when input provided by a user is stored and later rendered without proper sanitization, permitting code injection that can affect the integrity and confidentiality of the system and its data.

Affected Systems

Products affected include Webpros: WP Squared and Webpros: cPanel. Specific version information is not listed, suggesting that all versions may be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 9 indicates a high‑severity issue. No EPSS score is available, but the lack of a KEV listing does not diminish the impact of the vulnerability. The attack vector requires access to the WHM Mass Modify Accounts interface, typically available to administrators. An attacker with that access can supply malicious script that persists across sessions, leading to code execution on subsequent page loads. The exploit is straightforward once the authenticated interface is reached, making it likely to be abused if unattended.

Generated by OpenCVE AI on October 2, 2026 at 07:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest release of WP Squared and cPanel that contains the stored XSS fix
  • Contact Webpros support to confirm that the patch has been applied and request any additional guidance
  • Deploy web application firewall rules or content security policies to block XSS payloads in the WHM interface

Generated by OpenCVE AI on October 2, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Title Stored XSS Allowing Arbitrary Code Execution in WHM Mass Modify Accounts

Fri, 02 Oct 2026 06:45:00 +0000


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-10-02T06:20:44.084Z

Reserved: 2026-09-18T15:00:00.594Z

Link: CVE-2026-93697

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T07:16:38.893

Modified: 2026-10-02T07:16:38.893

Link: CVE-2026-93697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T07:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')