[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":38,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":45,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":51,"vulnerability-29484":58},[4,15,23,28],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":33,"targets":34,"cta":36,"variant":37,"campaign_id":30},"Office Hours #8 - AI Survey","office-hours-8","Free live Office Hours, Wed Jul 29: The triage tax - why AI finds more and proves less","https://zoom.us/webinar/register/5117815316917/WN_kMwWqNEwQJa8NvfsFw89vw",true,[35],"/","Save your spot","primary",["Island",39],{"key":40,"params":41,"result":43},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":42},"{}",{"head":44},{},["Island",46],{"key":47,"params":48,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":42},{"head":50},{},["Island",52],{"key":53,"params":54,"result":56},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":55},"{\"text-color\":\"gray\"}",{"head":57},{},{"id":59,"detectable_with":60,"vuln_details":67,"vuln_id":84,"name":85,"published":86,"updated":68},29484,{"tool":61,"engine":64},{"id":62,"name":63},1,"Network Scanner",{"id":65,"name":66},2,"Nuclei",{"id":59,"codename":68,"description":68,"severity":69,"risk_description":70,"public_description":71,"public_recommendation":72,"recommendation":68,"references":73,"cvssv3":78,"epss_score":79,"epss_percentile":80,"cve":81,"in_cisa_catalog":9,"date":83,"software_type":68,"vendor":68,"product":68,"ptt_exploit_capabilities":68},null,"critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the webserver's /rest/configure endpoint. The plugins query parameter is forwarded to the plugin manager without authentication, allowing an attacker to supply a URL to a remote Python file that Arelle downloads and executes within its process.","Upgrade to Arelle 2.39.10 or later, which rejects remote URL plug-in references over the webserver.",[74,75,76,77],"https://www.vulncheck.com/advisories/arelle-unauthenticated-rce-via-rest-configure","https://github.com/Arelle/Arelle/pull/2320","https://github.com/Arelle/Arelle/releases/tag/2.39.10","https://nvd.nist.gov/vuln/detail/CVE-2026-42796",9.8,0.02415,0.82444,[82],"CVE-2026-42796","2026-05-04T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-42796","Arelle \u003C 2.39.10 - Remote Code Execution","2026-07-24T00:00:00Z"]