WebPros security advisory (AV26-961)

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Serial number: AV26-961Date: September 24, 2026 As of September 23, 2026, WebPros is affected by vulnerabilities in the following products: Plesk Versions 18.0.34 to 18.0.80.7 Version 18.0.81.0 Plesk extension "Plesk RESTful API" Versions 2.4.2 to 2.4.6 Plesk extension "Site Import" Prior to or equal to 1.12.1 WP Toolkit for cPanel Prior to or equal to 6.11.2-10794 cPanel/WHM Prior to 11.134.0.57 Prior to 11.136.0.41 Prior to 11.138.0.8 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerability CVE-2026-68492: Arbitrary code execution as root in Plesk via the Plesk RESTful API extension Vulnerability CVE-2026-87898: Arbitrary code execution as root in Plesk's Site Import extension Security: CVE-2026-87899 Vulnerability in cPanel's CalDAV/CardDAV - September 22, 2026 – cPanel Security: CVE-2026-87900 Vulnerability in WP Toolkit Database Creation - September 22, 2026 – cPanel

This version

Version
1 of 1
Recorded
September 24, 2026 15:00
Change
Initial
Content hash
aae592307aa4d4fdc8555acbfd291d5f
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.