Impact
An improper authorization flaw in the Plesk XML API allows an attacker who is already authenticated to inject arbitrary configuration directives. This injection enables them to write arbitrary files as root, leading to full privilege escalation and complete compromise of the server's integrity. The weakness is a combination of insufficient authorization controls (CWE-15) and code injection (CWE-94).
Affected Systems
The vulnerability affects all WebPros Plesk installations that expose the XML API. All versions lacking the vendor patch are potentially vulnerable; no specific build numbers are listed in the advisory.
Risk and Exploitability
The likely attack vector is an authenticated user with access to the Plesk XML API, which typically requires local or network-level access to the Plesk control panel. The CVSS score of 9.9 indicates critical severity, but the EPSS score of less than 1% reflects a low current exploitation probability. Although the issue is not listed in the CISA KEV catalog, the combination of high impact and the potential for complete system compromise make it a high priority for remediation.
OpenCVE Enrichment