WordPress
Last updated
Was this helpful?
Last updated
Was this helpful?
WPScan uses 2 kinds of BFA:
wp-login -> attempts to BF wp-login.php
*Plugin version requires Directory listing to be enabled.
A simple PHP web shell (obfuscate the file name).
Modify a less-used file of an inactive theme for avoiding breaking the site.
Interact with the shell via CLI.
-> uses WP's API to BF (xmlrpc.php
) (this is faster)