This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies.
Scanned 9/4/2026
Install to Claude Code
npx -y skills add gabrielmoreira/agent-skills-mirror --skill wordpress-penetration-testing --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Wordpress Penetration Testing?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gabrielmoreira-wordpress-penetration-testing)More formats (shields.io, HTML) on the badges page.
---
name: WordPress Penetration Testing
description: This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies.
metadata:
author: zebbern
version: 4.1.0-fractal
---
# WordPress Penetration Testing
## Purpose
Conduct comprehensive security assessments of WordPress installations including enumeration of users, themes, and plugins, vulnerability scanning, credential attacks, and exploitation techniques. WordPress powers approximately 35% of websites, making it a critical target for security testing.
## Prerequisites
## 🧠 Knowledge Modules (Fractal Skills)
### 1. [Required Tools](./sub-skills/required-tools.md)
### 2. [Required Knowledge](./sub-skills/required-knowledge.md)
### 3. [Phase 1: WordPress Discovery](./sub-skills/phase-1-wordpress-discovery.md)
### 4. [Phase 2: Basic WPScan Enumeration](./sub-skills/phase-2-basic-wpscan-enumeration.md)
### 5. [Phase 3: WordPress Version Detection](./sub-skills/phase-3-wordpress-version-detection.md)
### 6. [Phase 4: Theme Enumeration](./sub-skills/phase-4-theme-enumeration.md)
### 7. [Phase 5: Plugin Enumeration](./sub-skills/phase-5-plugin-enumeration.md)
### 8. [Phase 6: User Enumeration](./sub-skills/phase-6-user-enumeration.md)
### 9. [Phase 7: Comprehensive Enumeration](./sub-skills/phase-7-comprehensive-enumeration.md)
### 10. [Phase 8: Password Attacks](./sub-skills/phase-8-password-attacks.md)
### 11. [Phase 9: Vulnerability Exploitation](./sub-skills/phase-9-vulnerability-exploitation.md)
### 12. [Phase 10: Advanced Techniques](./sub-skills/phase-10-advanced-techniques.md)
### 13. [WPScan Enumeration Flags](./sub-skills/wpscan-enumeration-flags.md)
### 14. [Common WordPress Paths](./sub-skills/common-wordpress-paths.md)
### 15. [WPScan Command Examples](./sub-skills/wpscan-command-examples.md)
### 16. [Legal Considerations](./sub-skills/legal-considerations.md)
### 17. [Technical Limitations](./sub-skills/technical-limitations.md)
### 18. [Detection Evasion](./sub-skills/detection-evasion.md)
### 19. [WPScan Shows No Vulnerabilities](./sub-skills/wpscan-shows-no-vulnerabilities.md)
### 20. [Brute-Force Blocked](./sub-skills/brute-force-blocked.md)
### 21. [Cannot Access Admin Panel](./sub-skills/cannot-access-admin-panel.md)
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!