WordPress
Last updated
Last updated
Scan all plugins:
[!important] Always do full scans on plugins as many of them are vulnerable.
User Info:
Page Info:
Hunting for Credentials:
If we can read the wp-config.php file, it is possible to look for SQL database credentials:
Useful in Arbitrary File Read, or Privilege Escalation
Login Bruteforce:
Code Execution:
Requires Admin access. Inject this into a theme in Theme Editor:
Then visit the php page with ?cmd=<command>
Known Vulnerabilities:
Vulnerable Plugins - mail-masta
Vulnerable Plugins - wpDiscuz