Wordpress

  1. wpscan

  2. Enumerate -e (ap, vp, u)

  3. Use --api-token for vuln info

  4. Use --passwords for brute force

  5. If plugins can't be found, use all -e options and --plugins-detection aggressive

Last updated