Critical Analysis: CVE-2026-48172 - LiteSpeed cPanel Plugin Privilege Escalation Vulnerability... — May 29, 2026

Published 29 May 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news

By AGMP Partners Initial Discovery and Context Alright, let's talk about CVE-2026-48172. This one hits a pretty sweet spot for attackers, impacting the LiteSpeed Cache for WordPress (LSCWP) plugin, specifically when integrated with cPanel environments. The vulnerability surfaced on May 29, 2026, and it's a significant privilege escalation issue, allowing a low-privileged cPanel user to essentially gain root access to the underlying server. For anyone running WordPress sites on shared hosting or dedicated servers managed through cPanel, and utilizing LiteSpeed as their web server and caching solution, this is a critical flaw. We're looking at a CVSSv3.1 score likely in the 9.x range due to the ease of exploitation and the direct path to full system compromise. The sheer ubiquity of cPanel, LiteSpeed, and WordPress means the attack surface here is absolutely massive, and the exploit develo