← All cheat sheets

WPSCAN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

WPScan is a WordPress security scanner that detects known
vulnerabilities in WordPress core, plugins, and themes. It also
enumerates users, performs password brute forcing, and checks for
misconfigurations.

BASIC USAGE#

wpscan --url <target>            # Basic scan
wpscan --url <target> -e         # Enumerate everything
wpscan --url <target> --api-token <token>
                                 # Scan with vulnerability data

ENUMERATION (-e)#

wpscan --url <target> -e u       # Enumerate users
wpscan --url <target> -e u1-100  # Enumerate users (IDs 1-100)
wpscan --url <target> -e p       # Enumerate plugins (popular)
wpscan --url <target> -e ap      # Enumerate all plugins
wpscan --url <target> -e vp      # Enumerate vulnerable plugins
wpscan --url <target> -e t       # Enumerate themes (popular)
wpscan --url <target> -e at      # Enumerate all themes
wpscan --url <target> -e vt      # Enumerate vulnerable themes
wpscan --url <target> -e tt      # Enumerate timthumbs
wpscan --url <target> -e cb      # Enumerate config backups
wpscan --url <target> -e dbe     # Enumerate DB exports
wpscan --url <target> -e m       # Enumerate media IDs
wpscan --url <target> -e u,vp,vt # Combined enumeration

DETECTION MODES#

wpscan --url <target> --plugins-detection mixed
                                 # Mixed detection (default)
wpscan --url <target> --plugins-detection passive
                                 # Passive only
wpscan --url <target> --plugins-detection aggressive
                                 # Aggressive (more requests)

PASSWORD BRUTE FORCE#

wpscan --url <target> -U <user> -P <wordlist>
                                 # Brute force single user
wpscan --url <target> -U users.txt -P passwords.txt
                                 # Brute force user list
wpscan --url <target> -U admin -P rockyou.txt --max-threads 50
                                 # Fast brute force
wpscan --url <target> -U admin -P wordlist.txt --password-attack wp-login
                                 # Via wp-login.php
wpscan --url <target> -U admin -P wordlist.txt --password-attack xmlrpc
                                 # Via XML-RPC (faster)
wpscan --url <target> -U admin -P wordlist.txt --password-attack xmlrpc-multicall
                                 # XML-RPC multicall (fastest)

AUTHENTICATION OPTIONS#

wpscan --url <target> --cookie "name=value"
                                 # Use custom cookie
wpscan --url <target> --force     # Skip "is WordPress?" check
wpscan --url <target> --wp-content-dir <path>
                                 # Custom wp-content directory
wpscan --url <target> --wp-plugins-dir <path>
                                 # Custom plugins directory

PROXY & NETWORK#

wpscan --url <target> --proxy <proxy_url>
                                 # HTTP proxy
wpscan --url <target> --proxy-auth <user:pass>
                                 # Proxy authentication
wpscan --url <target> --random-user-agent
                                 # Random User-Agent per request
wpscan --url <target> --user-agent <agent>
                                 # Custom User-Agent
wpscan --url <target> --throttle <ms>
                                 # Delay between requests (ms)
wpscan --url <target> --max-threads <n>
                                 # Max concurrent threads
wpscan --url <target> --disable-tls-checks
                                 # Skip SSL certificate checks
wpscan --url <target> --stealthy
                                 # Stealthy scan (slower, fewer requests)

OUTPUT OPTIONS#

wpscan --url <target> -o out.txt      # Save output
wpscan --url <target> -f json         # JSON format
wpscan --url <target> -f cli          # CLI format (default)
wpscan --url <target> -f json -o out.json
                                      # JSON to file
wpscan --url <target> --verbose       # Verbose output
wpscan --url <target> --no-banner     # Suppress banner

API TOKEN#

# Get free API token at: https://wpscan.com/
# Provides vulnerability data for detected plugins/themes
wpscan --url <target> --api-token YOUR_TOKEN
# Or set env: export WPSCAN_API_TOKEN=YOUR_TOKEN
# Or config: ~/.wpscan/scan.yml

EXAMPLES#

# Full enumeration with API
wpscan --url https://example.com -e ap,at,u --api-token TOKEN

# Aggressive plugin scan
wpscan --url https://example.com -e ap --plugins-detection aggressive

# User enumeration + brute force
wpscan --url https://example.com -e u -U admin -P rockyou.txt

# Stealthy scan through proxy
wpscan --url https://example.com --stealthy --proxy http://127.0.0.1:8080

# Quick vulnerability check
wpscan --url https://example.com -e vp,vt --api-token TOKEN

# Full aggressive scan with output
wpscan --url https://example.com -e ap,at,u,cb,dbe --plugins-detection aggressive -f json -o results.json --api-token TOKEN

NOTES#

- Ruby-based tool
- API token highly recommended (free tier: 25 requests/day)
- XML-RPC multicall is fastest for brute forcing
- Aggressive mode sends many requests (may trigger WAF)
- --stealthy mode reduces detection risk
- Update database regularly: wpscan --update
- Can be installed via gem: gem install wpscan
- Docker available: docker run wpscanteam/wpscan