DigiTimber cPanel Integration
DigiTimber cPanel Integration has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for DigiTimber cPanel Integration has a vendor fix available, so running the current release closes it.
All of these findings were reported by Abdi Pranata. DigiTimber cPanel Integration is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-22690DigiTimber cPanel Integration <= 1.4.6 - Cross-Site Request Forgery to Stored Cross-site Scripting
Read the full analysisVulnerability Records

DigiTimber cPanel Integration
Author
DigiTimber
DigiTimber cPanel Integration allows users to access basic cPanel functionality from within WordPress. This plugin was created initially for our own users, but decided that with the lack of any other plugins in the list, we’d toss it out there for others. Hopefully its helpful to you and your users! Currently limited to email administration, but more is planned. – View a list of all email accounts for all domains. – Add a new email accounts to any domain registered in cpanel. – Update email account passwords and quotas. – Delete email accounts. In time we are hoping to add many functions from within the WordPress site that users would otherwise need to log into cPanel in order to access.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C