[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":66,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":73,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":79,"vulnerability-29577":86},[4,15,23,28,36,42,48,54,60],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":9,"targets":33,"cta":35,"variant":13,"campaign_id":30},"Compliance - Page Launch - Homepage","compliance-pages-launch","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.","https://pentest-tools.com/usage/compliance",[34],"/","Get compliance evidence",{"title":37,"slug":38,"text":39,"link":32,"external":9,"targets":40,"cta":35,"variant":13,"campaign_id":30},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[41],"/exploit-helpers/sniper",{"title":43,"slug":44,"text":45,"link":32,"external":9,"targets":46,"cta":35,"variant":13,"campaign_id":30},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?",[47],"/network-vulnerability-scanning/network-security-scanner-online",{"title":49,"slug":50,"text":51,"link":32,"external":9,"targets":52,"cta":35,"variant":13,"campaign_id":30},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[53],"/website-vulnerability-scanning/website-scanner",{"title":55,"slug":56,"text":57,"link":32,"external":9,"targets":58,"cta":35,"variant":13,"campaign_id":30},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[59],"/features/integrations",{"title":61,"slug":62,"text":63,"link":32,"external":9,"targets":64,"cta":35,"variant":13,"campaign_id":30},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[65],"/features/pentest-reporting",["Island",67],{"key":68,"params":69,"result":71},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":70},"{}",{"head":72},{},["Island",74],{"key":75,"params":76,"result":77},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":70},{"head":78},{},["Island",80],{"key":81,"params":82,"result":84},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":83},"{\"text-color\":\"gray\"}",{"head":85},{},{"id":87,"detectable_with":88,"vuln_details":95,"vuln_id":110,"name":111,"published":112,"updated":96},29577,{"tool":89,"engine":92},{"id":90,"name":91},1,"Network Scanner",{"id":93,"name":94},2,"Nuclei",{"id":87,"codename":96,"description":96,"severity":97,"risk_description":98,"public_description":99,"public_recommendation":100,"recommendation":96,"references":101,"cvssv3":104,"epss_score":105,"epss_percentile":106,"cve":107,"in_cisa_catalog":9,"date":109,"software_type":96,"vendor":96,"product":96,"ptt_exploit_capabilities":96},null,"high","Unauthenticated attackers can extract sensitive database information, leading to data disclosure.","The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","Update to the latest version of the My Calendar – Accessible Event Manager plugin.",[102,103],"https://wpscan.com/vulnerability/a6466f97-4d8a-4d01-b61f-94d89da7c16b/","https://nvd.nist.gov/vuln/detail/CVE-2026-6854",7.5,0.00953,0.5839,[108],"CVE-2026-6854","2026-07-08T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-6854","My Calendar \u003C 3.7.9 - Unauthenticated SQL Injection","2026-08-17T00:00:00Z"]