- Server operating system version
- Windows Server 2022
- Plesk version and microupdate number
- Plesk Obsidian v18.0.56
Hi everyone,
When creating an email account, by default the "Can be used to log in to Plesk" box is checked.
If left checked, the created user has the role of "application user" and if they log in to plesk they have access to the WP Toolkit and manage the website in this way.
On the other hand, in the "application user" role there are no permissions relating to the WP Toolkit.
This situation concerns us in terms of security.
First, the option "Can be used to log in to Plesk" should not be enabled by default.
Second, what really worries us, you should not have access to the WP Toolkit unless this is explicitly allowed in the role.
When creating an email account, by default the "Can be used to log in to Plesk" box is checked.
If left checked, the created user has the role of "application user" and if they log in to plesk they have access to the WP Toolkit and manage the website in this way.
On the other hand, in the "application user" role there are no permissions relating to the WP Toolkit.
This situation concerns us in terms of security.
First, the option "Can be used to log in to Plesk" should not be enabled by default.
Second, what really worries us, you should not have access to the WP Toolkit unless this is explicitly allowed in the role.