CVE-2026-93697

Summary

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.

Affected Software

VendorProductVersion RangeStatus
WebproscPanel0 < 11.138.0.11affected
WebproscPanel0 < 11.136.0.45affected
WebproscPanel0 < 11.134.0.61affected
WebproscPanel0 < 11.110.0.148affected
WebprosWP Squared0 < 11.138.1.13affected

Weaknesses

  • CWE-79: CWE-79 Cross-site Scripting (XSS) - Stored

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References