2.-Attacking-wordpress
1. Manual Code Execution via Theme Editor (404.php)
2. Metasploit wp_admin_shell_upload
3. mail-masta LFI Exploit
4. wpDiscuz RCE Exploit
Python Script Method
Curl Method
5. WordPress REST API User Enumeration
6. XML-RPC Brute Force (system.multicall)
7. wp-config.php Exposure Check
8. Web Shell Obfuscation Example
Last updated