Executive Summary

A critical stored XSS vulnerability, identified as CVE-2026-93029, has been discovered in the WHM Manage SSL Hosts interface of cPanel. This vulnerability allows for arbitrary code execution and has a CVSS score of 9. It affects multiple versions of cPanel and WP Squared.

Technical Analysis

The vulnerability is classified as a stored XSS (Cross-Site Scripting) issue. The attack vector involves a low-privileged user interacting with the WHM Manage SSL Hosts interface. The root cause of this vulnerability is the lack of proper input validation.

How It Gets Exploited

An attacker with low privileges, potentially a user of the cPanel system, could exploit this vulnerability by injecting malicious code into the WHM Manage SSL Hosts interface. When another user, likely with higher privileges, views or interacts with the affected section, the malicious code could be executed. This could lead to arbitrary code execution on the system, potentially allowing the attacker to gain higher privileges or access sensitive information.

Impact Assessment

The affected products and versions are: - cPanel: versions less than 11.138.0.11, 11.136.0.45, 11.134.0.61, and 11.110.0.148 - WP Squared: versions less than 11.138.1.13 The vulnerability has a CVSS score of 9, indicating a critical severity level. Successful exploitation could lead to arbitrary code execution, allowing an attacker to achieve high confidentiality, integrity, and availability impacts.

Recommended Actions

To mitigate this vulnerability, it is recommended to update cPanel and WP Squared to the following versions or later: - cPanel: 11.138.0.11 or higher - WP Squared: 11.138.1.13 or higher Additionally, users should ensure that they are not using affected versions of cPanel or WP Squared and should apply the necessary updates as soon as possible. Monitoring for suspicious activity in the WHM Manage SSL Hosts interface and implementing WAF rules to detect and prevent XSS attacks can also be beneficial.

Sources

- National Vulnerability Database (NVD) - cPanel Change Logs - WP Squared Change Log - HackerOne Reports