Impact
A path traversal weakness (CWE‑22) in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 permits a local user to manipulate file paths to read or write files outside the intended directories. Based on the description, it is inferred that the attacker can place malicious code in a location that Plesk will execute, allowing arbitrary code execution with root privileges. The result is a full compromise of confidentiality, integrity, and availability for the affected host.
Affected Systems
The vulnerability affects installations of Plesk by WebPros. All releases up to and including 18.0.79.9 and those from 18.0.80 through 18.0.80.5 are impacted.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The attack vector is local: a user who can log onto the system or otherwise obtain local access must exploit the path traversal to gain root‑level code execution. No remote exploitation path is documented in the available data.
OpenCVE Enrichment