Skip to main content
Hackviser Training

Hacking WordPress

9 sections3 tools

Training Overview

The "Hacking WordPress" training is designed to identify security vulnerabilities in WordPress-based websites. This comprehensive training thoroughly examines the structure of WordPress, and techniques for scanning core versions, plugins, and themes.

The training begins with an overview of the basic structure and components of WordPress applications. You will learn how to scan WordPress core versions, plugins, and themes, and how to identify security vulnerabilities. Additionally, you will gain practical knowledge on using the WPScan tool for vulnerability scanning and determining security issues. Throughout the training, detailed scanning and analysis methods using WPScan will be emphasized.

What you will learn

  • The fundamental structure of WordPress sites.
  • How to use WPScan to enumerate versions, plugins, themes, and users.
  • How to identify common vulnerabilities and misconfigurations in WordPress.
  • Essential hardening techniques to protect a WordPress installation.

Tools you will use

  • WPScan
  • Burp Suite
  • Directory scanning tools

Prerequisites

  • Basic understanding of web technologies.
  • Familiarity with the concept of a Content Management System (CMS).

Who this is for

  • Penetration Testers targeting WordPress sites.
  • WordPress administrators and developers.
  • Bug Bounty Hunters.

Training sections

  1. 1Introduction
  2. 2Structure of WordPress
  3. 3Collecting Information on WordPress Core Version
  4. 4Collecting Information on Plugins and Themes
  5. 5Collecting Information on Users
  6. 6WPScan
  7. 7WPScan Enumeration
  8. 8WordPress Hardening Techniques
  9. 9Exam

Continue learning

Practice the topic in a lab or continue with a related Hackviser guide.