All tools

Web Application

WPScan

WordPress vulnerability scanner for plugins, themes, users.

beginner
Linux
Docker
Enumeration
Exploitation

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Target runs WordPress and is in scope.

How

Enumerate users/plugins; check known vulns with API token.

Why

WordPress is common; dedicated scanner saves time.

Commands & usage

wpscan --url https://example.com --enumerate u,ap,at
wpscan --url https://example.com --api-token $WPSCAN_TOKEN

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

wordpress
cms

Related in Web Application