[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":38,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":45,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":51,"vulnerability-29477":58},[4,15,23,28],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":33,"targets":34,"cta":36,"variant":37,"campaign_id":30},"Office Hours #8 - AI Survey","office-hours-8","Free live Office Hours, Wed Jul 29: The triage tax - why AI finds more and proves less","https://zoom.us/webinar/register/5117815316917/WN_kMwWqNEwQJa8NvfsFw89vw",true,[35],"/","Save your spot","primary",["Island",39],{"key":40,"params":41,"result":43},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":42},"{}",{"head":44},{},["Island",46],{"key":47,"params":48,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":42},{"head":50},{},["Island",52],{"key":53,"params":54,"result":56},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":55},"{\"text-color\":\"gray\"}",{"head":57},{},{"id":59,"detectable_with":60,"vuln_details":67,"vuln_id":76,"name":77,"published":78,"updated":68},29477,{"tool":61,"engine":64},{"id":62,"name":63},1,"Network Scanner",{"id":65,"name":66},2,"Nuclei",{"id":59,"codename":68,"description":68,"severity":69,"risk_description":70,"public_description":71,"public_recommendation":72,"recommendation":68,"references":73,"cvssv3":68,"epss_score":68,"epss_percentile":68,"cve":68,"in_cisa_catalog":9,"date":68,"software_type":68,"vendor":68,"product":68,"ptt_exploit_capabilities":68},null,"medium","The risk exists that the data is unknowingly exposed to the internet, making it accessible to remote threat actors that can leverage it to attack the target, or the entire company, depending on the sensitivity of the data.","Detects a vLLM inference server exposing its OpenAI-compatible API without authentication. The /v1/models endpoint returns the list of served models and is reachable by any unauthenticated client, allowing model enumeration and unauthorized inference (resource abuse / cost and information exposure). vLLM does not enable an API key by default; it is only enforced when the server is started with --api-key.","We suggest restricting access to the exposed resource.",[74,75],"https://docs.vllm.ai/en/latest/serving/openai_compatible_server.html","https://github.com/vllm-project/vllm","NETSCAN-NUCLEI-EXPOSURES-VLLM-OPENAI-API-EXPOSED","vLLM OpenAI-Compatible API - Unauthenticated Exposure","2026-07-23T00:00:00Z"]