WordPress reconnaissance using Metasploit

Metasploit has a scanner module for WordPress to get the version number, wordpress_scanner.

Let's set the options for this module:

Once everything is set, let's run it:

This is a very simple scanner that tries to find the version number using the techniques mentioned previously.

Now that we have the version numbers, you can refer to the following case studies on how to enumerate and exploit WordPress vulnerabilities. The vulnerabilities given are explained in detail.