WPSploit Logo

WPSploit

0
Free
Visit Website

WPSploit is a repository designed for creating and/or porting specific exploits for WordPress using Metasploit as an exploitation tool. It currently contains 45 modules (15 exploits and 30 auxiliaries). For usage, download the modules to a directory, and refer to the official documentation of Metasploit for loading external modules. All modules are based on the WPScan Vulnerability Database (WPVDB). For contributions, fork the repository, create a new feature branch, commit changes, and create a new pull request. Questions and suggestions can be sent to robertoespreto[at]gmail.com.

FEATURES

ALTERNATIVES

Automatic tool for DNS rebinding-based SSRF attacks

A week-long series of articles and talks on evading Microsoft Advanced Threat Analytics (ATA) detection

A comprehensive .NET post-exploitation library designed for advanced security testing.

A unified repository for different Metasploit Framework payloads.

A Ruby framework designed to aid in the penetration testing of WordPress systems.

Pentest active directory LAB project for practicing attack techniques.

Using Apache mod_rewrite rules to rewrite incident responder or security appliance requests to an innocuous website or the target's real website.

A blog post about bypassing AppLocker using PowerShell diagnostic scripts