Back to search
CVE-2026-29202
Published: May 8, 2026
Modified: May 13, 2026
PUBLISHED
Description
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
| Vendor | Product | Versions |
|---|---|---|
WebPros | cPanel | affected 11.136.0.0 - < 11.136.0.9affected 11.134.0.0 - < 11.134.0.25affected 11.132.0.0 - < 11.132.0.31affected 11.130.0.0 - < 11.130.0.22affected 11.126.0.0 - < 11.126.0.58+6 more versions |
WebPros | cPanel (CloudLinux 6, CentOS 6) | affected 11.110.0.0 - < 11.110.0.116 |
WebPros | WP Squared | affected 11.136.1.0 - < 11.136.1.11 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now