[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":43,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":50,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":56,"vulnerability-29495":63},[4,15,23,28],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":9,"targets":33,"cta":42,"variant":13,"campaign_id":30},"DEF CON AI pentests launch","def-con-ai-pentests","We’re launching AI Pentests at DEF CON 34","https://pentest-tools.com/events/defcon-34-2026",[34,35,36,37,38,39,40,41],"/","/website-vulnerability-scanning/website-scanner","/network-vulnerability-scanning/network-security-scanner-online","/information-gathering/find-subdomains-of-domain","/network-vulnerability-scanning/port-scanner-online-nmap","/product","/website-vulnerability-scanning/discover-hidden-directories-and-files","/insights","See you there",["Island",44],{"key":45,"params":46,"result":48},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":47},"{}",{"head":49},{},["Island",51],{"key":52,"params":53,"result":54},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":47},{"head":55},{},["Island",57],{"key":58,"params":59,"result":61},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":60},"{\"text-color\":\"gray\"}",{"head":62},{},{"id":64,"detectable_with":65,"vuln_details":72,"vuln_id":88,"name":89,"published":90,"updated":73},29495,{"tool":66,"engine":69},{"id":67,"name":68},1,"Network Scanner",{"id":70,"name":71},2,"Nuclei",{"id":64,"codename":73,"description":73,"severity":74,"risk_description":75,"public_description":76,"public_recommendation":77,"recommendation":73,"references":78,"cvssv3":82,"epss_score":83,"epss_percentile":84,"cve":85,"in_cisa_catalog":9,"date":87,"software_type":73,"vendor":73,"product":73,"ptt_exploit_capabilities":73},null,"critical","An attacker can read sensitive server files or perform SSRF attacks against internal infrastructure.","Apache Tika versions 1.13 through 3.2.1 are vulnerable to XXE via malicious XFA in PDFs, allowing file read and SSRF attacks.","Upgrade to Apache Tika 3.2.2 or later.",[79,80,81],"https://lists.apache.org/thread/8xn3rqy6kz5b3l1t83kcofkw0w4mmj1w","https://lists.debian.org/debian-lts-announce/2025/10/msg00030.html","https://nvd.nist.gov/vuln/detail/CVE-2025-54988",9.8,0.09092,0.94801,[86],"CVE-2025-54988","2025-08-20T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2025-54988","Apache Tika - XXE Injection","2026-07-30T00:00:00Z"]