WebPros A.I CyberSecurity Scoring
WebPros
Company Information
Website:https://www.webpros.com
Employees number:731
Number of followers:4,000
NAICS:5112
Industry Type:Software Development
Homepage:webpros.com
WebPros Risk Score (AI oriented)
Between 700 and 749
WebProsSoftware Development
Updated:
04/08/2026
04/08/2026
749/1000
Moderate
Ba
WebPros Global Score (TPRM)
xxxx
WebProsSoftware Development
Score locked

WebProsModerate
Current Score
749Ba (MODERATE)
01000
2 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
749
AUGUST 2026
754
Vulnerability
04 Aug 2026 • WebPros
cPanel and WebPros: Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User
Critical Privilege-Escalation Flaw in cPanel & WHM Exposes Servers to Root-Level Compromise
749
CRITICAL-5
WEBCPA1785839895
Critical Privilege-Escalation Flaw in cPanel & WHM Exposes Servers to Root-Level Compromise
A severe vulnerability in cPanel & WHM (CVE-2026-58048) has been disclosed, allowing authenticated users to execute arbitrary SQL commands with full database administrative privileges. The flaw, which affects the platform’s database management functionality, could lead to root-level server compromise in certain configurations, particularly in shared hosting environments.
### Key Details
- Who: The vulnerability impacts all supported versions of cPanel & WHM prior to patched releases.
- What: An authenticated attacker with access to the MySQL or MariaDB feature can escalate privileges, bypassing assigned permissions to execute administrative SQL commands.
- Impact: Successful exploitation could enable attackers to:
- Access or exfiltrate sensitive customer databases.
- Modify database users and permissions.
- Extract credentials or deploy malicious triggers.
- Gain filesystem access, potentially leading to full server compromise.
- Where: The risk is highest in shared hosting environments, where multiple users share the same server.
- When: The flaw was disclosed by WebPros, with credit to security researcher Vincent55 Yang. No technical exploitation details have been publicly released.
### Mitigation & Patching
cPanel has released patched versions to address the issue:
- 11.110.0.137
- 11.118.0.71
- 11.126.0.78
- 11.134.0.48
- 11.136.0.32
- 138.1.6 (for WP2 deployments)
For administrators unable to patch immediately, a temporary mitigation involves revoking the MySQL feature from affected cPanel users via feature list management. Security teams are advised to review database audit logs for suspicious activity, such as unauthorized privilege assignments or unusual file-related operations.
Hosting providers should prioritize patching, as the severity of the flaw makes rapid remediation critical.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
754
JUNE 2026
754
MAY 2026
756
Vulnerability
29 May 2026 • WebPros
WebPros: Critical Plesk Vulnerability Enables Arbitrary Command Execution
Critical Plesk Vulnerability (CVE-2026-44962) Exposes Linux Servers to Full Takeover
753
CRITICAL-3
WEB1780309424
Critical Plesk Vulnerability (CVE-2026-44962) Exposes Linux Servers to Full Takeover
A severe security flaw in WebPros Plesk, a widely used web hosting control panel, has been discovered, allowing authenticated low-privilege attackers to execute arbitrary OS commands and gain full server control. Tracked as CVE-2026-44962, the vulnerability carries a CVSS 3.1 score of 10.0, the highest possible severity rating, posing a critical risk to Linux hosting environments globally.
The flaw resides in Plesk’s APS Application Catalog search functionality, where user-supplied input is improperly sanitized before being interpolated into XPath queries. Classified as CWE-643 (Improper Neutralization of Data within XPath Expressions), this injection vulnerability enables attackers to manipulate query structures, bypass security controls, and trigger unauthorized system-level operations.
Key Details:
- Disclosure Date: May 29, 2026 (via coordinated bug bounty program).
- Attack Requirements: Network-accessible, no user interaction, low attack complexity, and only a low-privilege authenticated session (e.g., a standard hosting account).
- Impact: Arbitrary OS command execution, full local privilege escalation, and high risk to confidentiality, integrity, and availability.
- Affected Systems: Plesk for Linux with the APS Catalog feature enabled.
This vulnerability follows a prior critical flaw (CVE-2025-66430) disclosed months earlier, which allowed privilege escalation via Apache configuration injection.
Patch & Mitigation:
Plesk released fixes on February 24–25, 2026, for the following versions:
- Plesk 18.0.76.2 (February 25, 2026)
- Plesk 18.0.75.1 (February 24, 2026)
Administrators are advised to apply updates immediately. For environments unable to patch, Plesk recommends disabling the APS Catalog feature by adding the following to `/usr/local/psa/admin/conf/panel.ini` and restarting services:
```
[aps]
enabled = off
```
The vulnerability was responsibly disclosed by security researcher Georgii Shutiaev, who coordinated with Plesk to ensure a patch was available before public release. Hosting providers, managed service providers, and enterprises running Plesk on Linux are urged to prioritize remediation due to the flaw’s high severity and ease of exploitation.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
APRIL 2026
756
MARCH 2026
756
FEBRUARY 2026
756
JANUARY 2026
756
DECEMBER 2025
756
NOVEMBER 2025
756
OCTOBER 2025
756
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for WebPros ??
What was WebPros's A.I Rankiteo Cyber Score in August 2026 ??
What was WebPros's A.I Rankiteo Cyber Score in July 2026 ??
What was WebPros's A.I Rankiteo Cyber Score in June 2026 ??
What was WebPros's A.I Rankiteo Cyber Score in May 2026 ??
What was WebPros's A.I Rankiteo Cyber Score in April 2026 ??
What was WebPros's A.I Rankiteo Cyber Score in March 2026 ??
What was WebPros's A.I Rankiteo Cyber Score in February 2026 ??
What was WebPros's A.I Rankiteo Cyber Score in January 2026 ??
What was WebPros's A.I Rankiteo Cyber Score in December 2025 ??
What was WebPros's A.I Rankiteo Cyber Score in November 2025 ??
What was WebPros's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on WebPros's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with WebPros ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view WebPros's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?