A critical security vulnerability affecting the LiteSpeed User-End cPanel Pluginis currently being actively exploited. The vulnerability is tracked as CVE-2026-48172 and has a maximum CVSS score of 10.

The vulnerability is related to incorrect privilege assignment, which could be exploited by an attacker to execute arbitrary scripts with elevated privileges. Any cPanel user (or an attacker with access to an account) can exploit the lsws.redisAble function to execute scripts as root.
See also: WordPress: New serious vulnerability in LiteSpeed Cache plugin
LiteSpeed cPanel Plugin: Which versions are affected and fix
– LiteSpeed User-End cPanel Plugin versions 2.3 to 2.4.4.
– Initial fix is in 2.4.5.
– After additional security review, it is recommended to upgrade to LiteSpeed WHM Plugin 5.3.1.0 which includes cPanel plugin v2.4.7 or later.
Why the vulnerability is so dangerous especially for shared hosting
In a shared hosting environment, a "simple" cPanel user corresponds to a client/tenant. If a vulnerability allows a jump from this level to root on the underlying server, then it could theoretically lead to:
– full control of the host,
– access to other customers' files/databases,
– installation of backdoors or webshells,
– ransomware on an entire node.
See also: Critical authentication vulnerability in cPanel – Update now

How to quickly check for traces (IoC) in logs
The available instructions include a handy grep that searches for calls of the suspicious function in the cPanel logs:
grep -rE “cpanel_jsonapi_func=redisAble” /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null
– If it returns no result, it does not appear to be an exploit attempt with this pattern.
– If it returns lines, assume that there was at least probing (and potentially exploitation). Record timestamps/users/IPs and initiate incident response.
What to do now (mitigation)
1) Upgrade: target LiteSpeed WHM Plugin 5.3.1.0 (bundled cPanel plugin 2.4.7+).
2) If you can't patch immediately: remove the user-end plugin (reduce attack surface). An example command has been published:
/usr/local/lsws/admin/misc/lscmctl cpanelplugin –uninstall
3) After patch/uninstall, check for:
– new users with sudo/root, changes to SSH authorized_keys,
– cron persistence,
– changes to file ownership/permissions,
– unknown binaries/processes,
– webshells in account directories.
See also: LiteSpeed Cache WordPress: New vulnerability allows XSS attacks

What does it mean for Greece / businesses / admins / users
– In Greece there are a large number of corporate sites/e-shops on shared hosting. For hosting providers and MSPs, the incident is “high priority” because a compromised cPanel account can become a complete server breach.
– For businesses: if you are hosted on a third-party provider, ask immediately if the plugin has been upgraded/removed and if logs have been checked.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
