A vulnerability labeled as critical has been found in WebPros cPanel and WP Sqaured. Affected by this issue is the function
create_user. Such manipulation of the argument plugin leads to privilege escalation.
This vulnerability is referenced as CVE-2026-29202. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.