menu icon
Go Back

Incident Report — Security Update: CVE-2026-41940 (cPanel & WHM / WP2)

calendar icon2026-05-05

news image

 

Summary

On April 28, 2026, a security vulnerability affecting cPanel & WHM environments was disclosed and assigned CVE-2026-41940. The vulnerability impacts the WP Toolkit (WP2) component and, under certain conditions, could allow unauthorized actions. Proservice immediately initiated an impact assessment across its managed infrastructure.

Technical Details

The vulnerability involves improper access control within the WP Toolkit (WP2) component in cPanel & WHM environments.

Affected Components

  • WP Toolkit (WP2)
  • cPanel & WHM installations running unpatched versions

Severity: High (Vendor Assessment)

  • Attack Vector: Authenticated / Restricted Access (context-dependent)
  • Impact: Potential unauthorized operations within WordPress environments

Risk Assessment

  • Spread: Limited to affected cPanel & WHM instances
  • Impact: Privilege abuse / Unauthorized actions
  • Exploitation: Context-dependent (often requires authentication)
  • Customer Risk: Medium → High, especially in shared hosting environments

Proservice Response Action Plan

  • Conducted a full infrastructure audit to identify affected systems.
  • Applied vendor-issued patches and security updates.
  • Updated WP Toolkit (WP2) to the latest secure version.
  • Verified the integrity of managed WordPress installations.
  • Strengthened access controls and continuous monitoring.
  • Reviewed system logs for any indicators of compromise.

Customer Impact

✓ Status: No exploitation attempts were detected.

No unauthorized access to customer data was identified, and all services continued operating normally without interruption.

Mitigation & Recommendations

  • Regularly update cPanel & WHM.
  • Keep WP Toolkit and WordPress installations fully updated.
  • Enable strong authentication, including Two-Factor Authentication (2FA).
  • Restrict administrative access to trusted personnel only.
  • Continuously monitor account logs and user activity.

Status

The vulnerability has been fully neutralized across the Proservice infrastructure. Continuous security monitoring and system hardening remain in effect.

Remediation Guide

/scripts/upcp --force

Update WP Toolkit from the WHM interface

systemctl restart cpanel

Enable Two-Factor Authentication (2FA)

Audit all WordPress installations