Skip to content

CMS (WordPress, Joomla, Drupal)

Content management systems run a huge share of the web, and their real surface is not the core —usually reasonably patched— but plugins, themes, and configuration. An “updated” WordPress with 30 plugins is 30 codebases of uneven quality exposed under one domain. The attack pattern is almost always the same: fingerprint → enumerate core/plugin/theme versions and users → known CVE or weak credential → shell.

The attacker needs no 0-day: they need one unpatched vulnerable plugin, a user with a reused password, or an exposed admin panel. Monoculture helps: the same version of plugin X is vulnerable on thousands of sites, so mass scanners find victims without targeting anyone specific.

# quick fingerprint
curl -s https://target/ | grep -i 'wp-content\|generator'
# readme with core version
curl -s https://target/readme.html | grep -i version
# plugins by path
https://target/wp-content/plugins/<plugin>/readme.txt
# enumerate users (several ways)
https://target/?author=1 -> redirects to /author/<login>/
https://target/wp-json/wp/v2/users -> JSON with logins

Reference tool:

wpscan --url https://target --enumerate u,vp,vt --api-token TOKEN
# u=users vp=vulnerable plugins vt=vulnerable themes
  • Brute force on xmlrpc.php: system.multicall allows hundreds of login attempts in a single request (amplification). If open, it massively speeds up brute forcing.
  • Login via wp-login.php with the enumerated user list + reused passwords.
  • Shell upload from admin: with panel access → Appearance → Theme Editor editing 404.php, or uploading a plugin ZIP with a webshell. Typical path after landing: /wp-content/uploads/ or /wp-content/plugins/<x>/.
  • Specific vulnerable plugin: nearly every WP RCE/SQLi/LFI lives here; identify the version and grab the PoC.
  • CVE-2022-21661 — SQLi in core WP_Query (patched in 5.8.3).
  • File Manager (wp-file-manager) CVE-2020-25213 — unauthenticated RCE, mass-exploited.
  • Elementor / Elementor Pro — multiple unauth RCE/file-upload bugs across versions.
  • CVE-2023-32243 (Essential Addons) — privilege escalation to any user (password reset).
# version
curl -s https://target/administrator/manifests/files/joomla.xml
curl -s https://target/language/en-GB/en-GB.xml
  • CVE-2023-23752 — unauthenticated info disclosure in the REST API: leaks the database username and password (/api/index.php/v1/config/application?public=true). Devastating and heavily exploited.
  • CVE-2015-8562 — RCE via deserialization in the User-Agent header (historical, still shows up).
  • Enumeration with joomscan.
# version
curl -s https://target/CHANGELOG.txt | head
  • CVE-2018-7600 (Drupalgeddon2) — unauth RCE via render arrays; one of the most exploited web bugs ever.
  • CVE-2018-7602 (Drupalgeddon3) — follow-up to the above.
  • CVE-2019-6340 — RCE via REST/JSON:API deserialization.
  • Enumeration with droopescan.
  • wpscan (WP), joomscan (Joomla), droopescan (Drupal, Silverstripe).
  • nuclei with http/cves/ and http/technologies/ templates for fingerprint + CVE at scale.
  • ffuf to fuzz hidden admin/plugin paths.

With an RCE plugin or a compromised admin: webshell, pivot into the server, theft of the user database (reusable hashes), defacement, malware/SEO-spam injection to every visitor.

  • Requests to xmlrpc.php with system.multicall, bursts against wp-login.php.
  • Access to /wp-json/wp/v2/users, ?author=N, joomla.xml, CHANGELOG.txt.
  • New files created in uploads/, modified theme .php files, new admin users.

Monitor file integrity (FIM) in the webroot, user-creation logs, and plugin/theme install logs.

  • Update core, plugins, and themes —and remove the ones you don’t use; every inactive plugin is still exposed code.
  • Disable xmlrpc.php if unused; restrict /wp-admin and /administrator by IP or 2FA.
  • Block user enumeration (REST users, ?author), disable the theme/plugin editor (DISALLOW_FILE_EDIT).
  • CMS-specific WAF (rules for known signatures), strict file permissions, disable PHP execution in uploads/.
  • Minimum-plugin principle: less surface, fewer inherited CVEs.

Isolate the site, hunt for webshells in uploads/ and themes, rotate all credentials and keys (wp-config.php salts), reinstall core from a clean source, and audit the database for injected users/options.

  • Which CMS and core version? (readme/CHANGELOG/manifests)
  • Plugins/themes at a known-vulnerable version? (wpscan/droopescan/joomscan)
  • Is user enumeration possible? (REST, ?author)
  • Is xmlrpc.php open? (brute-force amplification)
  • Admin panel exposed without 2FA / IP filtering?
  • File upload / theme editor reachable after login?
  • Unpatched critical CVEs? (Drupalgeddon, Joomla 2023-23752, WP file-manager)
  • Does uploads/ execute PHP?