wordpress-penetration-testing

Featured

Assess WordPress installations for common vulnerabilities and WordPress 7.0 attack surfaces.

Testing & QA 39,350 stars 6386 forks Updated today MIT

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

> AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments. # WordPress Penetration Testing ## WordPress 7.0 Security Considerations WordPress 7.0 (April 2026) introduces new features that create additional attack surfaces: ### Real-Time Collaboration (RTC) - Yjs CRDT sync provider endpoints - `wp_sync_storage` post meta - Collaboration session hijacking - Data sync interception ### AI Connector API - `/wp-json/ai/v1/` endpoints - Credential storage in Settings > Connectors - Prompt injection vulnerabilities - AI response manipulation ### Abilities API - `/wp-json/abilities/v1/` manifest exposure - Ability invocation endpoints - Permission boundary bypass - MCP adapter integration points ### DataViews - New admin interface endpoints - Client-side validation bypass - Filter/sort parameter injection ### PHP Requirements - PHP 7.2/7.3 no longer supported (upgrade attacks) - PHP 8.3+ recommended (new attack vectors) ## Purpose Conduct comprehensive security assessments of WordPress installations including enumeration of users, themes, and plugins, vulnerability scanning, credential attacks, and exploitation techniques. WordPress powers approximately 35% of websites, making it a critical target for security testing. ## Prerequisites ### Required Tools - WPScan (pre-installed in Kali Linux) - Metasploit Framework - Burp Suite or OWASP ZAP - Nmap for initial discovery - cURL or wget ### Re...

Details

Author
sickn33
Repository
sickn33/antigravity-awesome-skills
Created
4 months ago
Last Updated
today
Language
Python
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category

Testing & QA Solid

wordpress-penetration-testing

This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies.

4,222 Updated today
zebbern
Testing & QA Solid

wordpress-penetration-testing

This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies.

27,705 Updated today
davila7
Testing & QA Listed

wordpress-penetration-testing

This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies.

335 Updated today
aiskillstore
Data & Documents Featured

wordpress

Complete WordPress development workflow covering theme development, plugin creation, WooCommerce integration, performance optimization, and security hardening. Includes WordPress 7.0 features: Real-Time Collaboration, AI Connectors, Abilities API, DataViews, and PHP-only blocks.

39,350 Updated today
sickn33
AI & Automation Listed

wp-diagnose

Multi-probe diagnostic + security audit of a connected target — plugin conflicts, slow queries, large autoload options, broken images, PHP errors, outdated core/plugins/themes, weak admins. Phase = Debug.

1 Updated 3 days ago
nuttaruj