Guest User

nginx config plesk helper for CVE-2026-42945

a guest
May 13th, 2026
140
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 1.46 KB | None | 0 0
  1. #!/bin/bash
  2.  
  3. # Helper script to trigger from Plesk Events or on demand to fix flawed/
  4. # unsafe rewrite directives in nginx config files added by wp-toolkit or other tools
  5. # Related to CVE-2026-42945 Nginx Rift
  6. # Target core paths across the filesystem
  7. VHOST_DIR="/etc/nginx/plesk.conf.d/vhosts"
  8. SYSTEM_DIR="/var/www/vhosts/system"
  9.  
  10. # Force the execution block into a detached subshell wrapper
  11. (
  12.     # Wait 3 seconds to allow Plesk/wp-toolkit to completely finish writing files to disk
  13.     sleep 3
  14.  
  15.     # 1. Broadly sanitize any generated file in the active Nginx include path
  16.     if [ -d "$VHOST_DIR" ]; then
  17.         find "$VHOST_DIR" -type f \( -name "*.conf" -o -name "*.config" \) -exec sed -i \
  18.             -e 's|rewrite "\^/(?\!wp-admin/)" "/fake-author-scan" last;|rewrite \^/(\[\^w\]\[\^p\]\[\^-\].\*)\$ /fake-author-scan last;|g' {} +
  19.     fi
  20.  
  21.     # 2. Broadly sanitize the Plesk systemic internal tracker directories
  22.     if [ -d "$SYSTEM_DIR" ]; then
  23.         find "$SYSTEM_DIR" -type f -name "*.conf" -exec sed -i \
  24.             -e 's|rewrite "\^/(?\!wp-admin/)" "/fake-author-scan" last;|rewrite \^/(\[\^w\]\[\^p\]\[\^-\].\*)\$ /fake-author-scan last;|g' {} +
  25.     fi
  26.  
  27.     # 3. Perform a syntax test before committing to ensure zero web service downtime
  28.     /usr/sbin/nginx -t >/dev/null 2>&1
  29.     if [ $? -eq 0 ]; then
  30.         /etc/init.d/nginx reload >/dev/null 2>&1
  31.     fi
  32. ) &
  33.  
  34. # Exit immediately so Plesk finishes its repair loop without hanging
  35. exit 0
Advertisement
Add Comment
Please, Sign In to add comment