CVE-2026-93029: Stored XSS in the cPanel-WHM interface
This text was generated using artificial intelligence (AI).The NVD lists CVE-2026-93029 since October 2, 2026 as a stored XSS vulnerability in the WHM interface Manage SSL Hosts by WebPros cPanel. The CVSS score is 9.0.
WebPros cPanel has repeatedly drawn attention in recent months due to critical security findings. According to SecurityAffairs, CVE-2026-41940, an authentication bypass in cPanel and WHM with a CVSS score of 9.8, was recorded in the Known Exploited Vulnerabilities catalog as actively exploited by CISA in April 2026. In August 2026, a report on CVE-2026-58048 followed, a vulnerability that allowed authenticated users to execute SQL commands with root privileges. The accumulation of critical findings in WebPros products underscores the importance of continuous vendor risk monitoring for operators of cPanel and WHM installations.
Patch Status: fixed in cPanel 11.138.0.11, 11.136.0.45, 11.134.0.61 and 11.110.0.148 (LTS) as well as WP Squared 11.138.1.13 (cPanel advisory from September 29, 2026)
Technical Classification
According to the NVD, the stored XSS vulnerability in the WHM interface Manage SSL Hosts allows for the execution of arbitrary code. The assessment describes a network-based attack that requires low privileges and user interaction.
The published CVSS entry also indicates a scope change as well as high impacts on confidentiality, integrity, and availability. This information supports a prioritized technical review of the deployed cPanel and WHM instances.
Patch Status and Prioritization
cPanel has addressed CVE-2026-93029 with the security release from September 29, 2026 fixed. The correction is included in cPanel 11.138.0.11, 11.136.0.45, 11.134.0.61 and 11.110.0.148 (LTS) as well as WP Squared 11.138.1.13. Affected are the builds below these versions.
Recommended steps:
Determine installed branch and build per cPanel and WP-Squared instance.
Prioritize updating instances below the mentioned builds.
Check accounts with access to the WHM interface Manage SSL Hosts, as exploitation requires low permissions.
The CVSS rating does not replace an assessment of the respective environment. In particular, the existing permissions, the required user interaction, and the patch status of the affected cPanel and WHM installations are relevant for classification.
cPanel and WHM are used by numerous German and Austrian hosting providers. If the exploitation of this vulnerability occurs and personal data is involved, this can trigger a reporting obligation under the GDPR to the competent data protection authority within 72 hours (Art. 33 GDPR). NIS-2-compliant hosting providers in Germany and those subject to the Austrian NISG should specifically examine the vulnerability of their infrastructure.
LocateRisk: Visibility for publicly accessible cPanel and WHM systems
cPanel and WHM installations can be operated under customer domains and identified externally. LocateRisk supports making publicly accessible systems and deployed software visible in the context of EASM. This allows checking where cPanel or WHM instances are accessible under own domains — including forgotten subdomains or non-centrally recorded cloud assets.
The visibility of a system does not automatically prove the concrete vulnerability of an instance. Assessing CVE-2026-93029 still requires checking the patch status and configuration.
Additionally, LocateRisk C-VRM can capture alerts when critical vulnerabilities become known at providers like WebPros or when their security level changes — as shown by the recent surge of critical CVEs in cPanel. For this CVE, the visibility of one's publicly accessible systems combines two separate tasks with the manufacturer information check: the identification of potentially affected infrastructure and the organizational prioritization of the assessment.
Am I affected?
This affects cPanel/WHM and WP Squared in the versions mentioned above; the vulnerability is fixed in the mentioned builds. Those who want to know whether cPanel/WHM or WP Squared are even visible in their externally accessible infrastructure can check the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-93029 is a stored XSS vulnerability (CWE-79) in the WHM interface Manage SSL Hosts of WebPros cPanel. It allows for the execution of arbitrary code according to NVD and was published on October 02, 2026. The CVSS score is 9.0.
This affects installations of WebPros cPanel that use the WHM interface Manage SSL Hosts. An attack requires a network connection, low privileges, and user interaction. Affected are cPanel builds below 11.138.0.11, 11.136.0.45, 11.134.0.61, and 11.110.0.148 as well as WP Squared below 11.138.1.13.
Yes. cPanel fixed the vulnerability on September 29, 2026. The corrected builds are 11.138.0.11, 11.136.0.45, 11.134.0.61, and 11.110.0.148; for WP Squared, it is build 11.138.1.13.
Status: October 02, 2026. This post is for general informational purposes and is not legal, security, or action advice in individual cases. The IT security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee the timeliness, correctness, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-93029
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.