1
0
Fork 0
mirror of https://github.com/tldr-pages/tldr.git synced 2025-04-23 11:22:09 +02:00
tldr/pages/common/wpscan.md
bl-ue 8ebd171d6f
*: fix typos reported by Hunspell (#5848)
Co-authored-by: marchersimon <50295997+marchersimon@users.noreply.github.com>
Co-authored-by: Seth Falco <seth@falco.fun>
Co-authored-by: Patrice Denis <patricedenis@users.noreply.github.com>
2021-05-20 16:13:41 -04:00

1.1 KiB

wpscan

WordPress vulnerability scanner. More information: https://github.com/wpscanteam/wpscan.

  • Update the vulnerability database:

wpscan --update

  • Scan a WordPress website:

wpscan --url {{url}}

  • Scan a WordPress website, using random user agents and passive detection:

wpscan --url {{url}} --stealthy

  • Scan a WordPress website, checking for vulnerable plugins and specifying the path to the wp-content directory:

wpscan --url {{url}} --enumerate {{vp}} --wp-content-dir {{remote/path/to/wp-content}}

  • Scan a WordPress website through a proxy:

wpscan --url {{url}} --proxy {{protocol://ip:port}} --proxy-auth {{username:password}}

  • Perform user identifiers enumeration on a WordPress website:

wpscan --url {{url}} --enumerate {{u}}

  • Execute a password guessing attack on a WordPress website:

wpscan --url {{url}} --usernames {{username|path/to/usernames.txt}} --passwords {{path/to/passwords.txt}} threads {{20}}

wpscan --url {{url}} --api-token {{token}}