[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":53,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":60,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":66,"vulnerability-2322":73},[4,15,23,32,41,48],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Sniper)","wp2shell-sniper","Validate wp2shell: one-click detection & exploitation confirms exposed or patched WP targets","https://pentest-tools.com/pricing",false,[11],"exploit-helpers/sniper","Get it with Pentest Suite","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",[21],"/vulnerabilities-exploits/","See CVE details",{"title":24,"slug":25,"text":26,"link":27,"external":28,"targets":29,"cta":22,"variant":31,"campaign_id":14},"wp2shell (pricing)","wp2shell-p","Validate *wp2shell* exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452",true,[30],"/pricing","primary",{"title":14,"slug":14,"text":33,"link":8,"external":9,"targets":34,"cta":40,"variant":13,"campaign_id":14},"Validate wp2shell: one-click detection & exploitation confirms exposed or patched WP targets.",[35,36,37,38,39],"/","/network-vulnerability-scanning/network-security-scanner-online","/cms-vulnerability-scanning/wordpress-scanner-online-wpscan","/website-vulnerability-scanning/website-scanner","/product","Confirm the risk",{"title":42,"slug":43,"text":44,"link":8,"external":9,"targets":45,"cta":47,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.",[46],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":49,"slug":50,"text":44,"link":8,"external":9,"targets":51,"cta":47,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[52],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",["Island",54],{"key":55,"params":56,"result":58},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":57},"{}",{"head":59},{},["Island",61],{"key":62,"params":63,"result":64},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":57},{"head":65},{},["Island",67],{"key":68,"params":69,"result":71},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":70},"{\"text-color\":\"gray\"}",{"head":72},{},{"id":74,"detectable_with":75,"vuln_details":82,"vuln_id":100,"name":101,"published":102,"updated":83},2322,{"tool":76,"engine":79},{"id":77,"name":78},1,"Network Scanner",{"id":80,"name":81},2,"Nuclei",{"id":74,"codename":83,"description":83,"severity":84,"risk_description":85,"public_description":86,"public_recommendation":87,"recommendation":83,"references":88,"cvssv3":94,"epss_score":95,"epss_percentile":96,"cve":97,"in_cisa_catalog":9,"date":99,"software_type":83,"vendor":83,"product":83,"ptt_exploit_capabilities":83},null,"critical","The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.","The plugin does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique.","Update to the latest version of the WordPress Admin Word Count Column plugin (2.2 or higher) to fix the local file inclusion vulnerability.",[89,90,91,92,93],"https://packetstormsecurity.com/files/166476/WordPress-Admin-Word-Count-Column-2.2-Local-File-Inclusion.html","https://wordpress.org/plugins/admin-word-count-column/","https://wpscan.com/vulnerability/6293b319-dc4f-4412-9d56-55744246c990","https://nvd.nist.gov/vuln/detail/CVE-2022-1390","https://github.com/ARPSyndicate/cvemon",9.8,0.21881,0.97397,[98],"CVE-2022-1390","2022-04-25T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2022-1390","WordPress Admin Word Count Column 2.2 - Local File Inclusion","2023-07-04T00:00:00Z"]