• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Issue WP Toolkit reports plugin as 0.0 security risk yet Wordfence DB says it's 9.8 Critical..!

pleskuser67553

Regular Pleskian
Server operating system version
AlmaLinux 9.8 (Olive Jaguar)
Plesk version and microupdate number
Plesk Obsidian 18.0.80 Update #7
I have a WordPress site on a server which I thought was vulnerable, yet WP Toolkit is giving it an overall 0.1 Security Risk, so I've been going about my other business with a false sense of security. Other external tools have since reconfirmed its critically vulnerable status :eek:



I have tried:
  • Scanning the site for malware with Imunify and Wordfence - no malware
  • Verifying the WordPress core checksums - all green
  • Detaching, deleting .wp-toolkit-ignore and rescanning for the affected site
  • plesk ext wp-toolkit --clear-wpt-cache
After it is still reporting the same scores. The 9.8 CVE is highlighted below which WP Toolkit claims is "Low". This seems to me to be a very serious bug in WP Toolkit's security features :(

By the way, LayerSlider WP is also being reported with a 6.4 CVE on Wordfence https://www.wordfence.com/threat-in...cated-contributor-stored-cross-site-scripting

1789556107896.png
 
Hello,
Thank you for the report, we are already aware of this issue and plan to improve this in a nearest WP-Toolkit release.
At the moment the toolkit uses security ranking based on its mostly on the EPSS score, and we will improve the calculations to also reflect more the CVSS scores
 
Back
Top