cPanel has disclosed two security flaws that together pose a serious risk to shared hosting environments. The first, located in the CalDAV and CardDAV service, lets any user with a hosting account run arbitrary code with root privileges, granting full control of the server. The second bug resides in the WP Toolkit plugin, which is used to install and manage WordPress sites, and also allows an account to escalate privileges.
The company announced the issues on September 22, but no patches have been released yet. Because the vulnerabilities are in widely deployed hosting management software, the potential for abuse is high—especially in shared hosting setups where many accounts reside on a single machine. Until fixes arrive, administrators should restrict access to the affected services and watch for signs of compromise.
The two bugs are distinct but share a common theme: both let a low-privileged hosting account break out of its sandbox. While the CalDAV/CardDAV flaw is the more severe due to direct root access, the WP Toolkit issue broadens the attack surface. cPanel has not indicated whether the flaws are being actively exploited, but given the ease of exploitation implied by the disclosure, urgency is warranted.