[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":10,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":16,"all-banners":23,"vulnerability-29450":72},["Island",4],{"key":5,"params":6,"result":8},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":7},"{}",{"head":9},{},["Island",11],{"key":12,"params":13,"result":14},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":7},{"head":15},{},["Island",17],{"key":18,"params":19,"result":21},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":20},"{\"text-color\":\"gray\"}",{"head":22},{},[24,37,47,54,61,67],{"title":25,"slug":25,"text":26,"link":27,"external":28,"targets":29,"cta":35,"variant":36,"campaign_id":25},"wp2shell","Validate wp2shell: one-click detection & exploitation confirms exposed or patched WP targets.","https://pentest-tools.com/pricing",false,[30,31,32,33,34],"/","/network-vulnerability-scanning/network-security-scanner-online","/cms-vulnerability-scanning/wordpress-scanner-online-wpscan","/website-vulnerability-scanning/website-scanner","/product","Confirm the risk","secondary",{"title":38,"slug":39,"text":40,"link":41,"external":42,"targets":43,"cta":45,"variant":46,"campaign_id":25},"wp2shell (pricing)","wp2shell-p","Validate *wp2shell* exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",true,[44],"/pricing","See CVE details","primary",{"title":48,"slug":49,"text":50,"link":27,"external":28,"targets":51,"cta":53,"variant":36,"campaign_id":25},"wp2shell (Sniper)","wp2shell-sniper","Validate wp2shell: one-click detection & exploitation confirms exposed or patched WP targets",[52],"exploit-helpers/sniper","Get it with Pentest Suite",{"title":55,"slug":56,"text":57,"link":27,"external":28,"targets":58,"cta":60,"variant":36,"campaign_id":25},"wp2shell (CVE page - detection)","wp2shell-cve-page","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.",[59],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451","Explore plans",{"title":62,"slug":63,"text":64,"link":41,"external":28,"targets":65,"cta":45,"variant":36,"campaign_id":25},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain",[66],"/vulnerabilities-exploits/",{"title":68,"slug":69,"text":57,"link":27,"external":28,"targets":70,"cta":60,"variant":36,"campaign_id":25},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit",[71],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452",{"id":73,"detectable_with":74,"vuln_details":81,"vuln_id":96,"name":97,"published":98,"updated":82},29450,{"tool":75,"engine":78},{"id":76,"name":77},1,"Network Scanner",{"id":79,"name":80},2,"Nuclei",{"id":73,"codename":82,"description":82,"severity":83,"risk_description":84,"public_description":85,"public_recommendation":86,"recommendation":82,"references":87,"cvssv3":90,"epss_score":91,"epss_percentile":92,"cve":93,"in_cisa_catalog":42,"date":95,"software_type":82,"vendor":82,"product":82,"ptt_exploit_capabilities":82},null,"critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","Joomla Balbooa Forms contains an unrestricted file upload vulnerability caused by lack of authentication checks, letting unauthenticated attackers upload executable files and achieve remote code execution.","Update to the latest version of Balbooa Forms extension.",[88,89],"https://nvd.nist.gov/vuln/detail/CVE-2026-56291","https://www.cisa.gov/known-exploited-vulnerabilities-catalog",9.8,0.08635,0.9451,[94],"CVE-2026-56291","2026-07-09T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-56291","Balbooa Forms \u003C 2.4.1 - Unauthenticated Arbitrary File Upload","2026-07-18T00:00:00Z"]