• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Issue When Child Theme active WP Toolkit omits critically vulnerable Parent Theme from Vulnerable Components list

pleskuser67553

Regular Pleskian
Server operating system version
AlmaLinux 9.8 (Olive Jaguar)
Plesk version and microupdate number
Plesk Obsidian 18.0.80 Update #7
I have a WordPress site with a critically vulnerable Theme (as high as 9.9 CVSS on Patchstack). This Theme, like most themes that have been customised, has a Child Theme. The Child Theme is the Active Theme.

Although it sends out emails to say that the Parent Theme is vulnerable (but only with the latest vulnerability, not a list of all vulnerabilities affecting that version), WP Toolkit does not show the vulnerable Parent Theme in the list of Vulnerable Components tab on the Security Status flyout panel in the UI.

1789743222047.png

The only clue in the UI that the Parent Theme is vulnerable is in the Themes tab of the WordPress domain card showing, and clicking on that does not give any information about how vulnerable it is, only to say "This theme contains known vulnerabilities. Activating it can compromise your website's security" - An inexperienced user might assume that's okay because it's not active, but the active Child Theme depends on the "inactive" Parent Theme.

1789742625110.png

Could it be that the Child Theme configured incorrectly, or is this a bug in WP Toolkit, which should, in my opinion, always refer to the inactive Parent Theme when its Child Theme is active.
 
Back
Top