WordPress
Discovery
# Version in meta tag
curl -s http://TARGET | grep 'content="WordPress'
# Version in readme
curl -s http://TARGET/readme.html
# Login page
/wp-login.php
/wp-admin/http://TARGET/SHARE-NAME/
http://TARGET/SHARE-NAME/wp-login.phphttp://TARGET/assets/fonts/blog/wp-admin/
http://TARGET/assets/fonts/blog/wp-content/
http://TARGET/assets/fonts/blog/wp-includes/
http://TARGET/assets/fonts/blog/wp-login.phpWPScan Enumeration
Brute Force (WPScan)
Theme Editor RCE (Authenticated)
Database Admin Password Reset to Plugin Upload
Metasploit RCE
Exposed Installer Takeover
Malicious plugin upload (wordpwn)
Trigger URL
Vulnerable Plugins
AdRotate Banner Manager authenticated upload RCE
Simple File List 4.2.2 pre-auth RCE
Tutor LMS authenticated issues
mail-masta LFI (unauthenticated)
Site Editor 1.1.1 LFI (CVE-2018-7422)
wpDiscuz RCE (CVE-2020-24186)
Important Paths
Path
Description
Config File Locations
Last updated