cPanel Vulnerability Allows Hosting Accounts to Gain Root Access

A flaw in cPanel's CalDAV and CardDAV service lets any hosting account execute code as root, granting full server control. A second bug in the WP Toolkit plugin allows cross-account database changes. cPanel has released fixes for both.
The CalDAV and CardDAV service flaw is especially dangerous because it transforms a standard hosting account into one with root-level privileges. An attacker who gains access to any single account on a shared server could then seize control of the entire machine, including all other accounts and data residing on it.
The WP Toolkit vulnerability operates through a separate mechanism, enabling database modifications that cross account boundaries. Together, these issues present a layered threat to hosting environments. cPanel has already distributed patches for both problems, and administrators are advised to apply them promptly to close the exposure windows.
The combined impact of these vulnerabilities could be substantial for shared hosting providers, where many websites often share a single server. A root-level compromise could expose customer data, alter site content, or enable further malicious activity. Small businesses and individual users relying on shared hosting may face service interruptions or data loss. The cross-account database flaw could also affect WordPress deployments specifically. While fixes exist, administrators who delay updates may leave their infrastructure vulnerable to exploitation.