[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":10,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":16,"all-banners":23,"vulnerability-29486":58},["Island",4],{"key":5,"params":6,"result":8},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":7},"{}",{"head":9},{},["Island",11],{"key":12,"params":13,"result":14},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":7},{"head":15},{},["Island",17],{"key":18,"params":19,"result":21},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":20},"{\"text-color\":\"gray\"}",{"head":22},{},[24,35,43,48],{"title":25,"slug":26,"text":27,"link":28,"external":29,"targets":30,"cta":32,"variant":33,"campaign_id":34},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[31],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":36,"slug":37,"text":38,"link":39,"external":29,"targets":40,"cta":42,"variant":33,"campaign_id":34},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[41],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":44,"slug":45,"text":38,"link":39,"external":29,"targets":46,"cta":42,"variant":33,"campaign_id":34},"wp2shell (CVE page - detection)","wp2shell-cve-page",[47],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":49,"slug":50,"text":51,"link":52,"external":53,"targets":54,"cta":56,"variant":57,"campaign_id":50},"Office Hours #8 - AI Survey","office-hours-8","Free live Office Hours, Wed Jul 29: The triage tax - why AI finds more and proves less","https://zoom.us/webinar/register/5117815316917/WN_kMwWqNEwQJa8NvfsFw89vw",true,[55],"/","Save your spot","primary",{"id":59,"detectable_with":60,"vuln_details":67,"vuln_id":85,"name":86,"published":87,"updated":68},29486,{"tool":61,"engine":64},{"id":62,"name":63},1,"Network Scanner",{"id":65,"name":66},2,"Nuclei",{"id":59,"codename":68,"description":68,"severity":69,"risk_description":70,"public_description":71,"public_recommendation":72,"recommendation":68,"references":73,"cvssv3":79,"epss_score":80,"epss_percentile":81,"cve":82,"in_cisa_catalog":29,"date":84,"software_type":68,"vendor":68,"product":68,"ptt_exploit_capabilities":68},null,"medium","Unauthenticated attackers can upload files into the WordPress media library by pointing the server-side fetch at an attacker-controlled Canto API. This also enables SSRF via the fbc_app_api parameter.","The Canto plugin for WordPress is vulnerable to missing authorization in the copy-media.php upload flow. The file is directly accessible and accepts attacker-controlled parameters for the upload destination, allowing unauthenticated users to upload arbitrary files constrained to WordPress-allowed MIME types. The fbc_app_api parameter controls the domain WordPress fetches from via wp_safe_remote_get, enabling SSRF to attacker-controlled infrastructure.","Update Canto to version 3.1.2 or later.",[74,75,76,77,78],"https://nvd.nist.gov/vuln/detail/CVE-2026-3335","https://www.wordfence.com/threat-intel/vulnerabilities/id/0777f759-6980-4572-a866-0210bd5f5085?source=cve","https://plugins.trac.wordpress.org/browser/canto/tags/3.1.1/includes/lib/copy-media.php#L71","https://plugins.trac.wordpress.org/browser/canto/tags/3.1.1/includes/lib/copy-media.php#L152","https://plugins.trac.wordpress.org/browser/canto/tags/3.1.1/includes/lib/copy-media.php#L306",5.3,0.00969,0.583,[83],"CVE-2026-3335","2026-03-21T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-3335","Canto \u003C= 3.1.1 - Missing Authorization to Unauthenticated File Upload","2026-07-28T00:00:00Z"]