CVE-2026-58046: WebPros Plesk

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

Affected products

  • WebPros Plesk: before 18.0.79.4 (fixed in 18.0.79.4)

Published 2026-07-30. Last modified 2026-09-03.