[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":38,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":45,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":51,"vulnerability-29469":58},[4,15,23,28],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":33,"targets":34,"cta":36,"variant":37,"campaign_id":30},"Office Hours #8 - AI Survey","office-hours-8","Free live Office Hours, Wed Jul 29: The triage tax - why AI finds more and proves less","https://zoom.us/webinar/register/5117815316917/WN_kMwWqNEwQJa8NvfsFw89vw",true,[35],"/","Save your spot","primary",["Island",39],{"key":40,"params":41,"result":43},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":42},"{}",{"head":44},{},["Island",46],{"key":47,"params":48,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":42},{"head":50},{},["Island",52],{"key":53,"params":54,"result":56},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":55},"{\"text-color\":\"gray\"}",{"head":57},{},{"id":59,"detectable_with":60,"vuln_details":67,"vuln_id":76,"name":77,"published":78,"updated":68},29469,{"tool":61,"engine":64},{"id":62,"name":63},1,"Network Scanner",{"id":65,"name":66},2,"Nuclei",{"id":59,"codename":68,"description":68,"severity":69,"risk_description":70,"public_description":71,"public_recommendation":72,"recommendation":68,"references":73,"cvssv3":68,"epss_score":68,"epss_percentile":68,"cve":68,"in_cisa_catalog":9,"date":68,"software_type":68,"vendor":68,"product":68,"ptt_exploit_capabilities":68},null,"medium","The risk exists that a remote unauthenticated attacker could brute-force the login panel to gain access to the service as an authenticated user. If an authenticated vulnerability is present on the machine, it could also be leveraged to exploit the target, compromising the underlying system.","Prodigy, a commercial scriptable annotation tool by Explosion AI used to label training data for machine learning and NLP models, was detected. Its local web server (default port 8080, built on uvicorn/FastAPI) ships with no built-in authentication or user accounts by default and is designed to run on localhost or a trusted network. The annotation UI was found directly reachable to unauthenticated visitors.","We suggest restricting access in the configs, or placing the panel behind a firewall if it was left out by an oversight in configuration.",[74,75],"https://prodi.gy","https://prodi.gy/docs","NETSCAN-NUCLEI-EXPOSED-PANELS-PRODIGY-PANEL","Prodigy Annotation Tool - Unauthenticated Exposure","2026-07-23T00:00:00Z"]