githubEdit

finding

Enumeration

Type of users

Administrator
Editor: who can publish and manage all posts, including others.
Author: publish and manage their own posts.
Contributor: who writes and manage their own posts but cannot publish them.
Subscriber: Who can browse posts and edit their profile.

Identify WordPress version

/robots.txt
curl -s http://blog."$domain" | grep WordPress

Login Pages

/wp-admin/login.php
/wp-admin/wp-login.php
/login.php
/wp-login.php

Directories

/wp-content/uploads (must check)
/wp-content/plugins
/wp-content/themes
/wp-includes (WordPress core files)

WordPress core version enumeration


Manual enumeration

Take some time and manually browser to look through the page sources.

Check themes

Check plugins

Checking plugins/themes

Pretty print html

Gather version information about themes/plugins

Manual users enumeration

Automatic WordPress enumeration

Last updated