Skip to content
Threat Feed
medium advisory

Security Vulnerabilities in Plesk Management Interface and Extensions

WebPros has released security updates for Plesk and its Migrator and Site Import extensions to address critical vulnerabilities CVE-2026-65642 and CVE-2026-65647.

CVE search metadata

CVE search record: CVE-2026-65642. EPSS: 0.43%. KEV: no. Product: Plesk, Plesk Migrator, Plesk Site Import. Brief: Security Vulnerabilities in Plesk Management Interface and Extensions. Brief link: https://feed.craftedsignal.io/briefs/2026-08-webpros-advisory/

CVE search record: CVE-2026-65647. EPSS: 0.46%. KEV: no. Product: Plesk, Plesk Migrator, Plesk Site Import. Brief: Security Vulnerabilities in Plesk Management Interface and Extensions. Brief link: https://feed.craftedsignal.io/briefs/2026-08-webpros-advisory/

WebPros has issued a security advisory (AV26-854) identifying vulnerabilities impacting its flagship Plesk hosting management platform and several associated extensions. The flaws include CVE-2026-65642, which affects the Plesk database management interface, and CVE-2026-65647, which affects the Plesk Site Import and Plesk Migrator extensions. These vulnerabilities present risks to server security and database administration workflows. WebPros has released patched versions for Plesk (versions 18.0.79.8, 18.0.80.4, and later), Plesk Migrator (version 2.36.0 and later), and Plesk Site Import (version 1.12.1 and later). Administrators are encouraged to prioritize these updates to mitigate the risk of unauthorized database access or exploit attempts targeting the affected management extensions.

Impact

Successful exploitation of these vulnerabilities could result in unauthorized access, data exposure, or administrative disruption within the Plesk environment. Given that Plesk is widely utilized by hosting providers and site administrators to manage complex server configurations, these vulnerabilities could enable attackers to gain control over hosted databases or leverage administrative extension functions to impact multiple sites on a shared server.

Recommendation

  • Apply the security patches for Plesk by upgrading to version 18.0.79.8 or 18.0.80.4 immediately.
  • Update the Plesk Migrator extension to at least version 2.36.0.
  • Update the Plesk Site Import extension to at least version 1.12.1.
  • Audit administrative access logs for unusual activity targeting the Plesk database management interface or extension execution logs following the update.

Immediate actions

Patch Plesk and associated extensions to the versions specified in the advisory.

IT Operations 48h