Security
Loading…

CVE-2026-41940

UNKNOWNKnown Exploited
Description

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Timeline
Published:April 30th, 2026 12:00 AM
Last modified:April 30th, 2026 12:00 AM
Added to KEV:April 30th, 2026
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

WebPros

Products

cPanel & WHM and WP2 (WordPress Squared)
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute