[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":60,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":67,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":73,"vulnerability-27580":80},[4,15,23,32,41,48,53],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Sniper)","wp2shell-sniper","Validate wp2shell: one-click detection & exploitation confirms exposed or patched WP targets","https://pentest-tools.com/pricing",false,[11],"exploit-helpers/sniper","Get it with Pentest Suite","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",[21],"/vulnerabilities-exploits/","See CVE details",{"title":24,"slug":25,"text":26,"link":27,"external":28,"targets":29,"cta":22,"variant":31,"campaign_id":14},"wp2shell (pricing)","wp2shell-p","Validate *wp2shell* exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452",true,[30],"/pricing","primary",{"title":14,"slug":14,"text":33,"link":8,"external":9,"targets":34,"cta":40,"variant":13,"campaign_id":14},"Validate wp2shell: one-click detection & exploitation confirms exposed or patched WP targets.",[35,36,37,38,39],"/","/network-vulnerability-scanning/network-security-scanner-online","/cms-vulnerability-scanning/wordpress-scanner-online-wpscan","/website-vulnerability-scanning/website-scanner","/product","Confirm the risk",{"title":42,"slug":43,"text":44,"link":8,"external":9,"targets":45,"cta":47,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.",[46],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":49,"slug":50,"text":44,"link":8,"external":9,"targets":51,"cta":47,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[52],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":54,"slug":55,"text":56,"link":57,"external":28,"targets":58,"cta":59,"variant":31,"campaign_id":55},"Office Hours #8 - AI Survey","office-hours-8","Free live Office Hours, Wed Jul 29: The triage tax - why AI finds more and proves less","https://zoom.us/webinar/register/5117815316917/WN_kMwWqNEwQJa8NvfsFw89vw",[35],"Save your spot",["Island",61],{"key":62,"params":63,"result":65},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":64},"{}",{"head":66},{},["Island",68],{"key":69,"params":70,"result":71},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":64},{"head":72},{},["Island",74],{"key":75,"params":76,"result":78},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":77},"{\"text-color\":\"gray\"}",{"head":79},{},{"id":81,"detectable_with":82,"vuln_details":89,"vuln_id":104,"name":105,"published":106,"updated":90},27580,{"tool":83,"engine":86},{"id":84,"name":85},1,"Network Scanner",{"id":87,"name":88},2,"Nuclei",{"id":81,"codename":90,"description":90,"severity":91,"risk_description":92,"public_description":93,"public_recommendation":94,"recommendation":90,"references":95,"cvssv3":98,"epss_score":99,"epss_percentile":100,"cve":101,"in_cisa_catalog":9,"date":103,"software_type":90,"vendor":90,"product":90,"ptt_exploit_capabilities":90},null,"medium","Attackers can redirect users to malicious external websites through the xerror parameter, potentially enabling phishing attacks and credential theft.","A vulnerability in XWiki's WYSIWYG API allows an attacker to redirect users to arbitrary external URLs through the xerror parameter. This could be used in phishing attacks to redirect users to malicious websites.","Upgrade to the latest XWiki version that properly validates redirect URLs in the WYSIWYG API.",[96,97],"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-pjhg-9wr9-rj96","https://nvd.nist.gov/vuln/detail/CVE-2025-32970",5.4,0.00572,0.43873,[102],"CVE-2025-32970","2025-04-30T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2025-32970","XWiki WYSIWYG API - Open Redirect","2025-08-30T00:00:00Z"]