Status: KEV
| Advisory ID: CVE-2026-41940
Key Details
| CVE | CVE-2026-41940 |
| Vulnerability Name | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability |
| Affected products | WebPros cPanel & WHM and WP2 (WordPress Squared) |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-306 (Missing Authentication for Critical Function) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-04-30. |
| Exploitation prediction (EPSS) | 98.53% probability of exploitation in the next 30 days (100% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-05-03 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
What to Do
Monitor WebPros's web page for any future patch releases.
References
KEV Required Action