wordpress-penetration-testing - Assess WordPress installations for security vulnerabilities
Assess WordPress installations through discovery, enumeration, vulnerability scanning, credential testing, and exploitation techniques.
Tags
Updated: 2026-09-30Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Discover WordPress installations
- Enumerate versions and components
- Identify users, themes, and plugins
- Scan for vulnerabilities and misconfigurations
- Assess credential strength
- Document exploitation proof
Inputs
- Target WordPress URL
- WordPress usernames
- Password wordlists
- WPScan API token
- Attacker callback address
Outputs
- WordPress enumeration report
- Vulnerability assessment
- Credential assessment
- Exploitation proof
- Scan result files
Requirements
- Authorized security assessment
- WPScan
- Metasploit Framework
- Burp Suite or OWASP ZAP
- Nmap
- cURL or wget
- WordPress architecture knowledge
- Web application testing knowledge
- HTTP protocol knowledge
- OWASP Top 10 knowledge
