Plesk Password-Protected Directories Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in Plesk version 18.0, specifically within the Password-Protected Directories feature. This issue allows users to inject data into the Apache configuration, enabling them to execute commands as the root user. The vulnerability arises from incorrect access control, which could be exploited by any Plesk user with access to the feature.

Impact

Exploitation of this vulnerability could lead to unauthorized root-level access on the server.

Remediation

Users can update Plesk to the latest version to address this vulnerability. Instructions for updating Plesk are available in the Plesk update guide.

Added: Dec 12, 2025, 4:18 PM
Updated: Dec 12, 2025, 8:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.