• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Question if a wordpress website is hacked, can they damage my entire server?

giordanosoftware

New Pleskian
Server operating system version
ubuntu 22.04 lts
Plesk version and microupdate number
18.0.45
Hi everyone, as the title suggests, I have this great doubt .. but if a WordPress or prestashop site is hacked, etc., is the attack limited to the specific plesk account or can I suffer damage to my entire system? a thousand thanks
 
That entirely depends on how it was hacked. If they just exploited a rotten plugin you might be in luck. If they got shell access and managed further privilege escalation ... you're not.
 
That would only help against the hacker getting a leaked password and using it to get shell access the normal way.
The question here is whether the security hole they used to get in was big enough to give them shell access by other means.
 
The way Plesk is designed on the users ( domain accounts ) just allows most of the time access only to that user files. If you dont change the original permissions on the folders its likely it wont access other domains ( and clients ) on a server.
A secure setup is to deny shell access.
I modify my ssh to only accept keys
 
Back
Top