Impact
The vulnerability arises from an incorrect database cloning process in Plesk versions prior to 18.0.79.6 and 18.0.80.2. This flaw permits a user with low privileges, such as a customer or reseller, to execute arbitrary code on the system under the identity of the database server administrator. The weakness corresponds to CWE‑266, and the potential impact includes full privilege escalation and remote code execution that could compromise the entire hosting environment.
Affected Systems
Affected by this issue are WebPros Plesk installations running versions 18.0.52 up to (but not including) 18.0.79.6 and 18.0.80.2—that is, 18.0.52 through 18.0.79.5 and 18.0.80.1. All users with access to the Plesk control panel in these editions are at risk until the vulnerability is remediated.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity, and while the EPSS score is not available, the high score suggests that exploitation is realistic. Based on the description, it is inferred that the exploit can be performed remotely through the Plesk web interface, exploiting the database cloning feature that is currently unrestricted for low‑privileged users. The vulnerability has not been listed in the CISA KEV catalog, but its high impact warrants immediate attention.
OpenCVE Enrichment