Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Account Bypass in WordPress Toolkit Enables Arbitrary CLI Execution |
Fri, 12 Jun 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account. | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-06-12T15:34:38.290Z
Reserved: 2026-05-19T15:00:09.320Z
Link: CVE-2026-47365
Updated: 2026-06-12T15:34:26.632Z
Status : Awaiting Analysis
Published: 2026-06-12T04:17:05.107
Modified: 2026-06-12T16:08:20.803
Link: CVE-2026-47365
No data.
OpenCVE Enrichment
Updated: 2026-06-12T05:00:17Z