Critical cPanel Vulnerability Enables Root Code Execution via Hosting Accounts
A critical vulnerability in cPanel's CalDAV and CardDAV services allows hosting account holders to execute code as root and gain full server control, while another flaw in the WP Toolkit plugin enables database modifications across accounts. Affected versions require immediate updates to mitigate risks of privilege escalation and data exposure.
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.
A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.
cPanel has released fixed versions for both,
*** END OF TRANSMISSION ***