WordPress Common Bugs
Introduction
What would you do if you came across a website that uses WordPress?
How to Detect
If you visit https://target.com and see the source code, you will see the links to themes and plugins from WordPress. Or you can visit https://target.com/wp-login.php, it is the WordPress login admin page
Find the related CVE by checking the core, plugins, and theme version
How to find the wordpress version
https://target.com/feed
https://target.com/?feed=rss2How to find the plugin version
https://target.com/wp-content/plugins/PLUGINNAME/readme.txt
https://target.com/wp-content/plugins/PLUGINNAME/readme.TXT
https://target.com/wp-content/plugins/PLUGINNAME/README.txt
https://target.com/wp-content/plugins/PLUGINNAME/README.TXTor change readme.txt to changelog.txt or readme.md
How to find the theme version
https://target.com/wp-content/themes/THEMENAME/style.css
https://target.com/wp-content/themes/THEMENAME/readme.txt (If they have readme file)If you found outdated core / plugins / themes, find the exploit at https://wpscan.com
Finding log files
Finding backup file wp-config
Get the username on the website
or
Bruteforce
or
XSPA in wordpress
Register enabled
Last updated