VendorscPanelwp_squaredall versions
Vulnerabilities

cPanel WP Squared

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2026-41940
WebPros cPanel and WHM Authentication Bypass via Login Flow
Published 2026-04-29 · Analyzed
9.8KEV1 PoCEPSS 0.985
CVE-2026-29205
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
Published 2026-05-13 · Analyzed
8.6EPSS 0.004
CVE-2026-32992
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
Published 2026-05-13 · Analyzed
8.2EPSS 0.003