The record
Written from the 1 report below. Nothing here is unsourced.
- A critical vulnerability in cPanel's CalDAV and CardDAV service allows an account holder to run code with root privileges.
- A separate bug in the WP Toolkit plugin enables users to modify databases belonging to other accounts.
- A third flaw allows local users to view other accounts' calendar and contact data.
- Hosting providers are urged to update cPanel & WHM and the WP Toolkit plugin immediately to mitigate these risks.
What to watch next
- Determination of whether the Plesk version of WP Toolkit is affected
- Clarity on whether automatic updates will correctly patch the WP Toolkit vulnerability
- Development of detection methods to identify if servers were compromised before patching
Coverage1
1 report
English national1
All filed from India
Named United States · Ali Mustafa · cPanel · WebPros
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
