CVE-2026-84069 PUBLISHED

WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php

Assigner: WPScan
Reserved: 01.09.2026 Published: 27.09.2026 Updated: 27.09.2026

The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.

Product Status

Vendor Unknown
Product WebFacing™
Versions Default: unaffected
  • affected from 5.3 to 5.4 (excl.)

Credits

  • nobody finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE