Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
WebPros

WebPros Vendor Cyber Rating & Cyber Score

webpros.com

WebPros, the largest web hosting software and automation company globally, manages 60 million domains and 27 million users. We unite top providers in web hosting, billing automation, infrastructure, server management, and online marketing software to help our partners and customers succeed within the Web Enablement Ecosystem. Our industry-leading brands include cPanel, Plesk, SolusVM, WHMCS, XOVI, Sitejet, 360 Monitoring, SocialBee, and Comet Backup.


WebPros A.I CyberSecurity Scoring

WebPros
Company Information
Website:https://www.webpros.com
Employees number:731
Number of followers:4,000
NAICS:5112
Industry Type:Software Development
Homepage:webpros.com
WebPros Risk Score (AI oriented)
Between 700 and 749
logo
WebProsSoftware Development
Updated:
04/08/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
WebPros Global Score (TPRM)
xxxx
logo
WebProsSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

WebProsModerate
Current Score
749Ba (MODERATE)
01000
2 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
749Before Incident
AUGUST 2026
754Before Incident
Vulnerability
04 Aug 2026WebPros
cPanel and WebPros: Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User

Critical Privilege-Escalation Flaw in cPanel & WHM Exposes Servers to Root-Level Compromise

749After Incident
CRITICAL-5
WEBCPA1785839895
Critical Privilege-Escalation Flaw in cPanel & WHM Exposes Servers to Root-Level Compromise A severe vulnerability in cPanel & WHM (CVE-2026-58048) has been disclosed, allowing authenticated users to execute arbitrary SQL commands with full database administrative privileges. The flaw, which affects the platform’s database management functionality, could lead to root-level server compromise in certain configurations, particularly in shared hosting environments. ### Key Details - Who: The vulnerability impacts all supported versions of cPanel & WHM prior to patched releases. - What: An authenticated attacker with access to the MySQL or MariaDB feature can escalate privileges, bypassing assigned permissions to execute administrative SQL commands. - Impact: Successful exploitation could enable attackers to: - Access or exfiltrate sensitive customer databases. - Modify database users and permissions. - Extract credentials or deploy malicious triggers. - Gain filesystem access, potentially leading to full server compromise. - Where: The risk is highest in shared hosting environments, where multiple users share the same server. - When: The flaw was disclosed by WebPros, with credit to security researcher Vincent55 Yang. No technical exploitation details have been publicly released. ### Mitigation & Patching cPanel has released patched versions to address the issue: - 11.110.0.137 - 11.118.0.71 - 11.126.0.78 - 11.134.0.48 - 11.136.0.32 - 138.1.6 (for WP2 deployments) For administrators unable to patch immediately, a temporary mitigation involves revoking the MySQL feature from affected cPanel users via feature list management. Security teams are advised to review database audit logs for suspicious activity, such as unauthorized privilege assignments or unusual file-related operations. Hosting providers should prioritize patching, as the severity of the flaw makes rapid remediation critical.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Data Compromised: Sensitive customer databases, credentials, payment information riskSystems Affected: cPanel & WHM servers (shared hosting environments)Operational Impact: Potential full server compromise, unauthorized database modificationsIdentity Theft Risk: YesPayment Information Risk: Yes
DATA BREACH
Customer databasesCredentialsSensitivity Of Data: HighData Exfiltration: PotentialPersonally Identifiable Information: Potential
JULY 2026
754Before Incident
JUNE 2026
754Before Incident
MAY 2026
756Before Incident
Vulnerability
29 May 2026WebPros
WebPros: Critical Plesk Vulnerability Enables Arbitrary Command Execution

Critical Plesk Vulnerability (CVE-2026-44962) Exposes Linux Servers to Full Takeover

753After Incident
CRITICAL-3
WEB1780309424
Critical Plesk Vulnerability (CVE-2026-44962) Exposes Linux Servers to Full Takeover A severe security flaw in WebPros Plesk, a widely used web hosting control panel, has been discovered, allowing authenticated low-privilege attackers to execute arbitrary OS commands and gain full server control. Tracked as CVE-2026-44962, the vulnerability carries a CVSS 3.1 score of 10.0, the highest possible severity rating, posing a critical risk to Linux hosting environments globally. The flaw resides in Plesk’s APS Application Catalog search functionality, where user-supplied input is improperly sanitized before being interpolated into XPath queries. Classified as CWE-643 (Improper Neutralization of Data within XPath Expressions), this injection vulnerability enables attackers to manipulate query structures, bypass security controls, and trigger unauthorized system-level operations. Key Details: - Disclosure Date: May 29, 2026 (via coordinated bug bounty program). - Attack Requirements: Network-accessible, no user interaction, low attack complexity, and only a low-privilege authenticated session (e.g., a standard hosting account). - Impact: Arbitrary OS command execution, full local privilege escalation, and high risk to confidentiality, integrity, and availability. - Affected Systems: Plesk for Linux with the APS Catalog feature enabled. This vulnerability follows a prior critical flaw (CVE-2025-66430) disclosed months earlier, which allowed privilege escalation via Apache configuration injection. Patch & Mitigation: Plesk released fixes on February 24–25, 2026, for the following versions: - Plesk 18.0.76.2 (February 25, 2026) - Plesk 18.0.75.1 (February 24, 2026) Administrators are advised to apply updates immediately. For environments unable to patch, Plesk recommends disabling the APS Catalog feature by adding the following to `/usr/local/psa/admin/conf/panel.ini` and restarting services: ``` [aps] enabled = off ``` The vulnerability was responsibly disclosed by security researcher Georgii Shutiaev, who coordinated with Plesk to ensure a patch was available before public release. Hosting providers, managed service providers, and enterprises running Plesk on Linux are urged to prioritize remediation due to the flaw’s high severity and ease of exploitation.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: Plesk for Linux with APS Catalog feature enabledOperational Impact: Full server control, arbitrary OS command execution, local privilege escalation
APRIL 2026
756Before Incident
MARCH 2026
756Before Incident
FEBRUARY 2026
756Before Incident
JANUARY 2026
756Before Incident
DECEMBER 2025
756Before Incident
NOVEMBER 2025
756Before Incident
OCTOBER 2025
756Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for WebPros ?
?
What was WebPros's A.I Rankiteo Cyber Score in August 2026 ?
?
What was WebPros's A.I Rankiteo Cyber Score in July 2026 ?
?
What was WebPros's A.I Rankiteo Cyber Score in June 2026 ?
?
What was WebPros's A.I Rankiteo Cyber Score in May 2026 ?
?
What was WebPros's A.I Rankiteo Cyber Score in April 2026 ?
?
What was WebPros's A.I Rankiteo Cyber Score in March 2026 ?
?
What was WebPros's A.I Rankiteo Cyber Score in February 2026 ?
?
What was WebPros's A.I Rankiteo Cyber Score in January 2026 ?
?
What was WebPros's A.I Rankiteo Cyber Score in December 2025 ?
?
What was WebPros's A.I Rankiteo Cyber Score in November 2025 ?
?
What was WebPros's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on WebPros's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with WebPros ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view WebPros's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
WebPros Cyber Scoring History | Rankiteo