The LiteSpeed User-End cPanel Plugin vulnerability is a serious reminder that hosting control panels and plugins are high-value targets because they sit close to websites, accounts, and server administration. The flaw, tracked as CVE-2026-48172 with a CVSS score of 10.0, is already being exploited in the wild and allows any cPanel user, including a compromised account, to abuse the lsws.redisAble function to execute arbitrary scripts as root. That is not a “plugin issue”; that is a server ownership problem wearing a plugin badge.
The vulnerability affects LiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4, while the WHM plugin itself is not directly impacted. LiteSpeed fixed the issue in cPanel plugin 2.4.5, and later released additional hardening through WHM Plugin 5.3.1.0, bundled with cPanel plugin 2.4.7 or higher. Since active exploitation has been reported, affected hosting providers should treat this as urgent rather than waiting for “normal maintenance,” that magical phrase attackers never respect.
Administrators should immediately upgrade to the latest LiteSpeed WHM Plugin version, check logs for the indicator cpanel_jsonapi_func=redisAble, and review any suspicious IP addresses or unexpected script execution activity. If immediate patching is not possible, LiteSpeed recommends uninstalling the user-end plugin using the provided lscmctl cpanelplugin --uninstall command.
The bigger lesson is that shared hosting environments must be hardened as multi-tenant security zones. A single compromised cPanel account should never be able to escalate into root-level execution. Hosting providers should enforce plugin patching, least privilege, account isolation, strict logging, webshell monitoring, file-integrity checks, and rapid incident response. Control panels make administration easier, which is lovely, until one vulnerable function gives attackers the same convenience.

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions. "Any cPanel user (including an attacker or a compromised account) may
Source: LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root via The Hacker News — published 23 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.