CMS (WordPress, Joomla, Drupal)
Content management systems run a huge share of the web, and their real surface is not the core —usually reasonably patched— but plugins, themes, and configuration. An “updated” WordPress with 30 plugins is 30 codebases of uneven quality exposed under one domain. The attack pattern is almost always the same: fingerprint → enumerate core/plugin/theme versions and users → known CVE or weak credential → shell.
Threat model
Section titled “Threat model”The attacker needs no 0-day: they need one unpatched vulnerable plugin, a user with a reused password, or an exposed admin panel. Monoculture helps: the same version of plugin X is vulnerable on thousands of sites, so mass scanners find victims without targeting anyone specific.
WordPress
Section titled “WordPress”Discovery and enumeration
Section titled “Discovery and enumeration”# quick fingerprintcurl -s https://target/ | grep -i 'wp-content\|generator'# readme with core versioncurl -s https://target/readme.html | grep -i version# plugins by pathhttps://target/wp-content/plugins/<plugin>/readme.txt# enumerate users (several ways)https://target/?author=1 -> redirects to /author/<login>/https://target/wp-json/wp/v2/users -> JSON with loginsReference tool:
wpscan --url https://target --enumerate u,vp,vt --api-token TOKEN# u=users vp=vulnerable plugins vt=vulnerable themesBy hand / exploitation
Section titled “By hand / exploitation”- Brute force on xmlrpc.php:
system.multicallallows hundreds of login attempts in a single request (amplification). If open, it massively speeds up brute forcing. - Login via
wp-login.phpwith the enumerated user list + reused passwords. - Shell upload from admin: with panel access → Appearance → Theme Editor editing
404.php, or uploading a plugin ZIP with a webshell. Typical path after landing:/wp-content/uploads/or/wp-content/plugins/<x>/. - Specific vulnerable plugin: nearly every WP RCE/SQLi/LFI lives here; identify the version and grab the PoC.
CVEs and real-world cases (WordPress)
Section titled “CVEs and real-world cases (WordPress)”- CVE-2022-21661 — SQLi in core WP_Query (patched in 5.8.3).
- File Manager (wp-file-manager) CVE-2020-25213 — unauthenticated RCE, mass-exploited.
- Elementor / Elementor Pro — multiple unauth RCE/file-upload bugs across versions.
- CVE-2023-32243 (Essential Addons) — privilege escalation to any user (password reset).
Joomla
Section titled “Joomla”# versioncurl -s https://target/administrator/manifests/files/joomla.xmlcurl -s https://target/language/en-GB/en-GB.xml- CVE-2023-23752 — unauthenticated info disclosure in the REST API: leaks the database username and password (
/api/index.php/v1/config/application?public=true). Devastating and heavily exploited. - CVE-2015-8562 — RCE via deserialization in the User-Agent header (historical, still shows up).
- Enumeration with joomscan.
Drupal
Section titled “Drupal”# versioncurl -s https://target/CHANGELOG.txt | head- CVE-2018-7600 (Drupalgeddon2) — unauth RCE via render arrays; one of the most exploited web bugs ever.
- CVE-2018-7602 (Drupalgeddon3) — follow-up to the above.
- CVE-2019-6340 — RCE via REST/JSON:API deserialization.
- Enumeration with droopescan.
Red Team — tools
Section titled “Red Team — tools”- wpscan (WP), joomscan (Joomla), droopescan (Drupal, Silverstripe).
- nuclei with
http/cves/andhttp/technologies/templates for fingerprint + CVE at scale. - ffuf to fuzz hidden admin/plugin paths.
Impact
Section titled “Impact”With an RCE plugin or a compromised admin: webshell, pivot into the server, theft of the user database (reusable hashes), defacement, malware/SEO-spam injection to every visitor.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- Requests to
xmlrpc.phpwithsystem.multicall, bursts againstwp-login.php. - Access to
/wp-json/wp/v2/users,?author=N,joomla.xml,CHANGELOG.txt. - New files created in
uploads/, modified theme.phpfiles, new admin users.
Telemetry
Section titled “Telemetry”Monitor file integrity (FIM) in the webroot, user-creation logs, and plugin/theme install logs.
Hardening
Section titled “Hardening”- Update core, plugins, and themes —and remove the ones you don’t use; every inactive plugin is still exposed code.
- Disable
xmlrpc.phpif unused; restrict/wp-adminand/administratorby IP or 2FA. - Block user enumeration (REST users,
?author), disable the theme/plugin editor (DISALLOW_FILE_EDIT). - CMS-specific WAF (rules for known signatures), strict file permissions, disable PHP execution in
uploads/. - Minimum-plugin principle: less surface, fewer inherited CVEs.
Response
Section titled “Response”Isolate the site, hunt for webshells in uploads/ and themes, rotate all credentials and keys (wp-config.php salts), reinstall core from a clean source, and audit the database for injected users/options.
Testing checklist
Section titled “Testing checklist”- Which CMS and core version? (readme/CHANGELOG/manifests)
- Plugins/themes at a known-vulnerable version? (wpscan/droopescan/joomscan)
- Is user enumeration possible? (REST,
?author) - Is
xmlrpc.phpopen? (brute-force amplification) - Admin panel exposed without 2FA / IP filtering?
- File upload / theme editor reachable after login?
- Unpatched critical CVEs? (Drupalgeddon, Joomla 2023-23752, WP file-manager)
- Does
uploads/execute PHP?