Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
aeondave avatar

Wpscan

  • 2 installs
  • 12 repo stars
  • Updated August 4, 2026
  • aeondave/malskill

wpscan is a Claude Code reference skill for WPScan, a WordPress vulnerability and enumeration scanner.

About

wpscan is a Claude Code reference skill for WPScan, a WordPress vulnerability and enumeration scanner. It documents enumeration of users, plugins, and themes, CVE lookups via the API token, password attacks over wp-login and XML-RPC, authenticated scanning, and common findings. Pentesters use it to assess WordPress sites during authorized security testing.

  • Reference for WPScan WordPress vulnerability and enumeration scanning
  • Covers user/plugin/theme enumeration, CVE lookups, and password attacks
  • Documents authenticated scanning and xmlrpc/wp-login brute-force modes

Wpscan by the numbers

  • 2 all-time installs (skills.sh)
  • Ranked #1,788 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

wpscan capabilities & compatibility

Free non-commercial license; a WPScan API token is required for CVE data.

Capabilities
wordpress pentest · vuln scanning · credential brute force
Use cases
security audit
Platforms
Linux · macOS · Windows
Pricing
Freemium
From the docs

What wpscan says it does

WordPress vulnerability and enumeration scanner.
SKILL.md
| `--api-token <token>` | WPScan API token (required for CVE data) |
SKILL.md
npx skills add https://github.com/aeondave/malskill --skill wpscan

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs2
repo stars12
Last updatedAugust 4, 2026
Repositoryaeondave/malskill

What it does

Enumerate users, plugins, and themes and find known vulnerabilities on a WordPress site during authorized testing.

Who is it for?

Authorized WordPress recon, vulnerable-plugin discovery, and user enumeration.

Skip if: Non-WordPress targets or scanning sites you are not authorized to test.

When should I use this skill?

You are assessing a WordPress site for vulnerable plugins/themes or exposed users.

By the numbers

  • 9 common findings tabled
  • default max-threads 5

Files

SKILL.mdMarkdownGitHub ↗

WPScan

WordPress vulnerability and enumeration scanner.

Quick Start

wpscan --url https://target.com
wpscan --url https://target.com --enumerate u,p,t --api-token <TOKEN>
wpscan --url https://target.com -U admin -P /usr/share/wordlists/rockyou.txt

Core Flags

FlagPurpose
--url <url>Target WordPress URL
--enumerate <items>u=users, p=plugins, t=themes, vp=vuln plugins, vt=vuln themes, ap=all plugins, at=all themes, tt=timthumbs, cb=config backups, dbe=db exports, m=media ids
--api-token <token>WPScan API token (required for CVE data)
--plugins-detectionaggressive / passive / mixed
--themes-detectionaggressive / passive / mixed
-U <user>Username (or file) for brute-force
-P <wordlist>Password wordlist
--password-attackxmlrpc / xmlrpc-multicall / wp-login
--usernames <list>Usernames to brute-force (comma-sep or file)
--proxy <proxy>HTTP proxy (e.g., http://127.0.0.1:8080)
--cookie <str>Cookie for authenticated scans
--headers <str>Custom HTTP headers
--http-auth <u:p>HTTP basic auth
-o <file>Output file
--format <fmt>cli / json / cli-no-colour
--throttle <ms>Milliseconds between requests
--request-timeout <n>Timeout per request
--connect-timeout <n>Connection timeout
--max-threads <n>Max concurrent threads (default 5)
--wp-content-dir <dir>Override wp-content dir if non-standard
--wp-plugins-dir <dir>Override plugins dir
--disable-tls-checksSkip SSL verification
--ignore-main-redirectDon't follow main domain redirect
--forceProceed even if target isn't WordPress
--updateUpdate WPScan database
-v / --verboseVerbose output
--stealthyPassive detection only + random UA

Enumeration Targets

# Users only (fastest, high value)
wpscan --url https://target.com --enumerate u

# Vulnerable plugins only (most impactful)
wpscan --url https://target.com --enumerate vp --api-token $TOKEN

# Full aggressive enum
wpscan --url https://target.com \
    --enumerate ap,at,u,tt,cb,dbe \
    --plugins-detection aggressive \
    --api-token $TOKEN

# Config backups (wp-config.php.bak, wp-config.php~, etc.)
wpscan --url https://target.com --enumerate cb

# Database exports
wpscan --url https://target.com --enumerate dbe

Password Attacks

# Brute-force via wp-login.php (slower, stealthier)
wpscan --url https://target.com \
    --usernames admin \
    --passwords /usr/share/wordlists/rockyou.txt \
    --password-attack wp-login

# XML-RPC multicall (faster, bypasses rate limiting)
wpscan --url https://target.com \
    --usernames admin \
    --passwords /usr/share/wordlists/rockyou.txt \
    --password-attack xmlrpc-multicall

# Enumerate users first, then attack
wpscan --url https://target.com --enumerate u --api-token $TOKEN -o users.json --format json
cat users.json | jq -r '.users[].username' > found_users.txt
wpscan --url https://target.com -U found_users.txt -P passwords.txt

Authenticated Scanning

# With session cookie (login via browser first)
wpscan --url https://target.com \
    --cookie "wordpress_logged_in_xxx=admin%7C..."

# With admin credentials (finds more plugins/themes)
wpscan --url https://target.com \
    --enumerate ap \
    --username admin --password 'AdminPass123!' \
    --plugins-detection aggressive

Common Findings

FindingImpact
Outdated plugins with CVEsRCE / LFI / SQLi
User enumeration via author archiveEnables password attacks
xmlrpc.php enabledBrute-force amplification (multicall = 500 tries/request)
readme.html / license.txtWordPress version disclosure
Timthumb vulnerabilityRemote code execution
Debug log exposed (/wp-content/debug.log)Info disclosure, credentials
Config backup (wp-config.php.bak)Database credentials
DB export in web rootFull database dump
Registration openAccount creation → plugin exploit

Common Workflows

# Quick recon pass
wpscan --url https://target.com --enumerate u,vp,vt \
    --api-token $TOKEN -o wp_scan.json --format json

# Parse JSON output for CVEs
cat wp_scan.json | jq '.plugins | to_entries[] | {plugin: .key, vulns: .value.vulnerabilities}'

# Stealthy scan (minimize fingerprint)
wpscan --url https://target.com --stealthy --enumerate u \
    --throttle 2000

# Through proxy for manual review
wpscan --url https://target.com --proxy http://127.0.0.1:8080 \
    --disable-tls-checks --enumerate u,vp --api-token $TOKEN

Key Attack Paths

1. Enumerate users → brute-force weak passwords → admin access → RCE via theme editor
2. Find vulnerable plugin (CVE) → exploit SQLi/LFI/RCE directly
3. xmlrpc.php enabled → multicall brute-force (bypass account lockout)
4. Config backup found → extract DB creds → wp_users table → crack password hashes
5. Registration enabled + vulnerable plugin → account takeover chain

Resources

FileWhen to load
references/wordpress-testing.mdXML-RPC abuse, REST API enum, auth bypass, manual exploitation

Related skills

FAQ

Do I need an API token?

Yes, the WPScan API token is required for CVE data on plugins and themes.

What is the fastest high-value enumeration?

Users-only enumeration (--enumerate u) is the fastest and high value.

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.