websavers Posted 2 hours ago Share Posted 2 hours ago This is related to this vulnerability in Plesk API: https://support.plesk.com/hc/en-us/articles/42139500580119-Vulnerability-CVE-2026-58046-Blind-SQL-injection-in-Plesk-s-XML-RPC-API Plesk has been pushing out automatic workarounds for a vulnerability to version 18.0.78. The workaround disables access using older Plesk API versions, and will block WHMCS SSO. Since the actual solution to the vulnerability has been applied in 18.0.79 Update #4 it seems the strict API version checking isn't necessary. That means to resolve this you only need to update Plesk to 18.0.79 Update #4. If you wish to stay on an earlier version of Plesk, it will either be vulnerable or inaccessible through WHMCS's SSO function unless WHMCS changes the Plesk API version that they connect with. Updating to the latest version of Plesk is simpler and something you can do rather than waiting on WHMCS devs. 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.