> For the complete documentation index, see [llms.txt](https://hexisanoob.gitbook.io/hexisanoob/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hexisanoob.gitbook.io/hexisanoob/enum-and-initial-compromise/web-pentest/wordpress-exploitation.md).

# Wordpress Exploitation

Learnt while Tryhackme: MrRobot. Will be updated as I keep learning newer thing

## [WPScan](#undefined)

### 1) Enumeration

A) Bruteforce and login

`sudo wpscan --url http://10.10.67.231/wp-login --usernames Elliot --passwords /home/kali/tryhackme/mrrobot/fsocity-sorted.dic`

B) Vulnerability Scanning

`wpscan --url yourwebsite.com -e vt (Vulnerable themes) (-e=enumerate)`\
`wpscan --url yourwebsite.com -e vp (Vulnerable plugins)`\
`wpscan --url yourwebsite.com -e <options> --api-token YOUR_TOKEN (Authenticated scan)`\
`wpscan --url yourwebsite.com -e u (Enumerate Users)`

### 2) Exploitation

There exists many exploitation mechanisms. First, I'll talk about editing the PHP code in the theme.\
Scenario: I was able to find credentials=> Elliot:ER28-0652\
I logged in to the admin panel and found out the code for the theme was editable<br>

![](https://62284611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MSvRnuhl_P5WCd1fZEn%2Fuploads%2FxN4f5hBCjfaMMOmE9OZE%2Fimage.png?alt=media\&token=6cf485a1-0320-4a34-8aca-bca21b1447dc)

I simply edit this file and add my own reverse shell code here

<div align="left"><img src="https://62284611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MSvRnuhl_P5WCd1fZEn%2Fuploads%2F8LApYaxGR1c3IRXZRb6j%2Fimage.png?alt=media&amp;token=337a9146-7909-4868-8558-20ba86c26992" alt=""></div>

Successfully gained reverse shell

<div align="left"><img src="https://62284611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MSvRnuhl_P5WCd1fZEn%2Fuploads%2Fdep9hUQqJYHb8lvERNEo%2Fimage.png?alt=media&amp;token=9f243d41-41b8-4a8a-9fb7-3427b08c2c35" alt=""></div>
