WPSCAN
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
WPScan is a WordPress security scanner that detects known vulnerabilities in WordPress core, plugins, and themes. It also enumerates users, performs password brute forcing, and checks for misconfigurations.
BASIC USAGE#
wpscan --url <target> # Basic scan
wpscan --url <target> -e # Enumerate everything
wpscan --url <target> --api-token <token>
# Scan with vulnerability data
ENUMERATION (-e)#
wpscan --url <target> -e u # Enumerate users wpscan --url <target> -e u1-100 # Enumerate users (IDs 1-100) wpscan --url <target> -e p # Enumerate plugins (popular) wpscan --url <target> -e ap # Enumerate all plugins wpscan --url <target> -e vp # Enumerate vulnerable plugins wpscan --url <target> -e t # Enumerate themes (popular) wpscan --url <target> -e at # Enumerate all themes wpscan --url <target> -e vt # Enumerate vulnerable themes wpscan --url <target> -e tt # Enumerate timthumbs wpscan --url <target> -e cb # Enumerate config backups wpscan --url <target> -e dbe # Enumerate DB exports wpscan --url <target> -e m # Enumerate media IDs wpscan --url <target> -e u,vp,vt # Combined enumeration
DETECTION MODES#
wpscan --url <target> --plugins-detection mixed
# Mixed detection (default)
wpscan --url <target> --plugins-detection passive
# Passive only
wpscan --url <target> --plugins-detection aggressive
# Aggressive (more requests)
PASSWORD BRUTE FORCE#
wpscan --url <target> -U <user> -P <wordlist>
# Brute force single user
wpscan --url <target> -U users.txt -P passwords.txt
# Brute force user list
wpscan --url <target> -U admin -P rockyou.txt --max-threads 50
# Fast brute force
wpscan --url <target> -U admin -P wordlist.txt --password-attack wp-login
# Via wp-login.php
wpscan --url <target> -U admin -P wordlist.txt --password-attack xmlrpc
# Via XML-RPC (faster)
wpscan --url <target> -U admin -P wordlist.txt --password-attack xmlrpc-multicall
# XML-RPC multicall (fastest)
AUTHENTICATION OPTIONS#
wpscan --url <target> --cookie "name=value"
# Use custom cookie
wpscan --url <target> --force # Skip "is WordPress?" check
wpscan --url <target> --wp-content-dir <path>
# Custom wp-content directory
wpscan --url <target> --wp-plugins-dir <path>
# Custom plugins directory
PROXY & NETWORK#
wpscan --url <target> --proxy <proxy_url>
# HTTP proxy
wpscan --url <target> --proxy-auth <user:pass>
# Proxy authentication
wpscan --url <target> --random-user-agent
# Random User-Agent per request
wpscan --url <target> --user-agent <agent>
# Custom User-Agent
wpscan --url <target> --throttle <ms>
# Delay between requests (ms)
wpscan --url <target> --max-threads <n>
# Max concurrent threads
wpscan --url <target> --disable-tls-checks
# Skip SSL certificate checks
wpscan --url <target> --stealthy
# Stealthy scan (slower, fewer requests)
OUTPUT OPTIONS#
wpscan --url <target> -o out.txt # Save output
wpscan --url <target> -f json # JSON format
wpscan --url <target> -f cli # CLI format (default)
wpscan --url <target> -f json -o out.json
# JSON to file
wpscan --url <target> --verbose # Verbose output
wpscan --url <target> --no-banner # Suppress banner
API TOKEN#
# Get free API token at: https://wpscan.com/ # Provides vulnerability data for detected plugins/themes wpscan --url <target> --api-token YOUR_TOKEN # Or set env: export WPSCAN_API_TOKEN=YOUR_TOKEN # Or config: ~/.wpscan/scan.yml
EXAMPLES#
# Full enumeration with API wpscan --url https://example.com -e ap,at,u --api-token TOKEN # Aggressive plugin scan wpscan --url https://example.com -e ap --plugins-detection aggressive # User enumeration + brute force wpscan --url https://example.com -e u -U admin -P rockyou.txt # Stealthy scan through proxy wpscan --url https://example.com --stealthy --proxy http://127.0.0.1:8080 # Quick vulnerability check wpscan --url https://example.com -e vp,vt --api-token TOKEN # Full aggressive scan with output wpscan --url https://example.com -e ap,at,u,cb,dbe --plugins-detection aggressive -f json -o results.json --api-token TOKEN
NOTES#
- Ruby-based tool - API token highly recommended (free tier: 25 requests/day) - XML-RPC multicall is fastest for brute forcing - Aggressive mode sends many requests (may trigger WAF) - --stealthy mode reduces detection risk - Update database regularly: wpscan --update - Can be installed via gem: gem install wpscan - Docker available: docker run wpscanteam/wpscan