<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — WebPros</title><description>Actively exploited vulnerabilities affecting WebPros products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/webpros.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-41940 — WebPros cPanel &amp; WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-41940</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-41940</guid><description>This vulnerability allows unauthenticated remote attackers to bypass the login process entirely and gain full access to cPanel &amp; WHM or WP2 control panels without valid credentials. Because these panels control web hosting environments — including DNS, email, databases, and file management — a successful attack can lead to complete server compromise. The fact that ransomware groups are already actively exploiting this flaw makes it an urgent, high-priority threat for any organization running affected WebPros products.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><category>WebPros</category><category>cPanel &amp; WHM and WP2 (WordPress Squared)</category></item></channel></rss>