How to do Penetration Testing with your WordPress Website

May 1, 2017 | Views: 7724

Begin Learning Cyber Security for FREE Now!

FREE REGISTRATIONAlready a Member Login Here

WordPress is a free online Open source content Managed system focused on PHP and MySQL. It is one the powerful and most used blogging tool.

As there is too many up’s and down’s in WordPress usage, it requires a security improvement, so the penetration test is essential to find the vulnerabilities and to secure you WordPress powered blog.

Security researcher Daniel Cid says, in 2016 At least 15,769 WordPress websites – and probably more – have been compromised. With Sucuri report almost 78% of infected websites were built on the WordPress platform.

WordPress penetration testing with WPScan

WPscan is a WordPress vulnerability scanner created by Ryan Dewhurst and it was sponsored by Sucuri.It comes pre-installed with BackBox Linux, Kali Linux, Pentoo, SamuraiWTF, BlackArch and it will not support windows.

With Wpscan we can enumerate theme, plugins, users, HTTP proxy and Wpscan will not check the source code of the page.

To Enumerate WordPress version, theme and plugin

wpscan –url –enumerate p

wpscan –url –enumerate t

How to Do Penetration testing with your WordPress website

To Enumerate WordPress users

wpscan –url –enumerate u


How to Do Penetration testing with your WordPress website

To launch a brute-force attack

wpscan –url –wordlist /root/Desktop/password.txt –username kcwto

How to Do Penetration testing with your WordPress website

To Enumerate timthumbs

If you are still using TimThumb, even after a very serious vulnerability, you have one more reason to be concerned.

wpscan –url –enumerate tt

How to Do Penetration testing with your WordPress website

To store Output in a separate File

wpscan –url –debug-output 2>debug.log

Penetration testing is an art and the active analysis depends upon the security researcher, here we evaluated some of the basic and important checks that need to be with the WordPress powered website.


You Can find more Infosec resources and security news in our Website


Share with Friends
Use Cybytes and
Tip the Author!
Share with Friends
Ready to share your knowledge and expertise?
  1. Hi, I observed in brute force attack in your password it emitted empty values. I am facing the same problem, the password field is empty. How do I get the password?

  2. Gud post…
    just missing 1 thing …
    cybrarians can set up their own wordpress lab by using turkney wordpress iso

Comment on This

You must be logged in to post a comment.

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Support Cybrary

Donate Here to Get This Month's Donor Badge


We recommend always using caution when following any link

Are you sure you want to continue?