[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":76,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":83,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":89,"vulnerability-29667":96},[4,15,23,28,37,43,49,55,61,66],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https:\u002F\u002Fpentest-tools.com\u002Fvulnerabilities-exploits\u002Fwordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"\u002Fvulnerabilities-exploits\u002F","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https:\u002F\u002Fpentest-tools.com\u002Fpricing",[21],"\u002Fvulnerabilities-exploits\u002Fwp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"\u002Fvulnerabilities-exploits\u002Fwordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":9,"targets":33,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",[34],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","compliance-pages-launch",{"title":38,"slug":39,"text":40,"link":32,"external":9,"targets":41,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[42],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":44,"slug":45,"text":46,"link":32,"external":9,"targets":47,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[48],"\u002Ffeatures\u002Fpentest-reporting",{"title":50,"slug":51,"text":52,"link":32,"external":9,"targets":53,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[54],"\u002Ffeatures\u002Fintegrations",{"title":56,"slug":57,"text":58,"link":32,"external":9,"targets":59,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[60],"\u002Fexploit-helpers\u002Fsniper",{"title":62,"slug":36,"text":63,"link":32,"external":9,"targets":64,"cta":35,"variant":13,"campaign_id":36},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[65],"\u002F",{"title":67,"slug":68,"text":69,"link":70,"external":71,"targets":72,"cta":75,"variant":13,"campaign_id":68},"Office Hours #11 - Compliance cycle survey","office-hours-11","[Live Office Hours, Wed Sept 9] Continuous compliance evidence: from automated tools or tired humans?","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_FLMs2-vyQbCTB67guMJH-Q",true,[65,73,74],"\u002Finsights\u002Fcompliance-cycles-survey","\u002Finsights","Save your spot",["Island",77],{"key":78,"params":79,"result":81},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":80},"{}",{"head":82},{},["Island",84],{"key":85,"params":86,"result":87},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":80},{"head":88},{},["Island",90],{"key":91,"params":92,"result":94},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":93},"{\"text-color\":\"gray\"}",{"head":95},{},{"id":97,"detectable_with":98,"vuln_details":105,"vuln_id":122,"name":123,"published":124,"updated":106},29667,{"tool":99,"engine":102},{"id":100,"name":101},1,"Network Scanner",{"id":103,"name":104},2,"Nuclei",{"id":97,"codename":106,"description":106,"severity":107,"risk_description":108,"public_description":109,"public_recommendation":110,"recommendation":106,"references":111,"cvssv3":116,"epss_score":117,"epss_percentile":118,"cve":119,"in_cisa_catalog":9,"date":121,"software_type":106,"vendor":106,"product":106,"ptt_exploit_capabilities":106},null,"medium","Authenticated attackers with administrator-level access can inject scripts that execute in other users' browsers.","The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ohmem-message' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","Update WP Content Permission to a version newer than 1.2.",[112,113,114,115],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fe44403cd-1cee-43c4-aabc-3eaad433c020?source=cve","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-content-permission\u002Ftags\u002F1.2\u002Fadmin\u002Fviews\u002Fadmin.php#L74","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-content-permission\u002Ftrunk\u002Fadmin\u002Fviews\u002Fadmin.php#L74","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-0743",4.4,0.00576,0.45367,[120],"CVE-2026-0743","2026-02-04T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-0743","WP Content Permission \u003C= 1.2 - Cross-Site Scripting","2026-08-30T00:00:00Z"]