Skip to content

Pentestblog

Menu
  • Home
  • Kali Linux
  • Blog
  • CTF Challenges
  • Course
    • Download Free Videos
  • Contact Us

How to Hack WordPress Websites

By Pentestblog 15/02/2021 WordPress Hacking 5 Comments
wordpress website hacking

Welcome back to you this blog. Today, I will show you  How to Hack WordPress websites. Our first step is to prepare the tool we will use. By the way, there are a bunch of WordPress Hacking tools available on the internet. But we will use this wpscan tool that is pre-installed in Kali Linux.

  • Virtualbox
  • Kali Linux / “Attacker”
  • Ubuntu machine “192.168.43.127”
  • wpscan
  • Nmap
  • dirb
  • Good wordlist

Imagine the scenario:

We stay located in a corporate network, and we desire to hack the WordPress website and obtain weaknesses in it. But this will be feasible only when you have the outer awareness of penetration testing. We can’t hack WordPress websites without the proper knowledge. To acquire more information, you will have to read this blog till the end. We want to say hacking is an art that enhances through hard work.

Let’s start, Hack WordPress website

The first step is to identify the target IP. for that, we will use the netdiscover command. This command will help you to discover the target IP. As you know, we have mentioned each blog. Look at the below image.

netdiscover

netdiscover

In the next stage! We will scan to the target using Nmap with IP address “192.168.43.127”, at the scanning stage using Nmap we can see open port ports that we can exploit, on there are three types of weakness. Look at the below image.

  • FTP (File transfer protocol)
  • SSH (Secure Shell)
  • HTTP (Hypertext transfer protocol)

nmap -sV -A 192.168.43.127

nmap scanning

Often, Hack WordPress websites, we need to scan our target URL. At this time, we will use the dirb tool.
DIRB is a tool designed to find these objects, hidden and not hidden.

dirb tool

In this stage! We try to open the WordPress URL in the browser and Open the WordPress login page. If you want to hack a WordPress website, then follow the below steps.

wordpress website
wordpress login page

In this stage! we will scan the vulnerable themes of the WordPress website. Without scanning WordPress themes and plugins, you can’t hack a WordPress website.

wpscan –url http://vtcsec/secret/ -e vt

vulnerable plugin

In this stage! We will enumerate the username of the WordPress website. For that, we will use the wpscan tool. wpscan is pre-install in Kali Linux. Using wpscan, you can Brute-force attack on username and password.

wpscan –url http://vtcsec/secret/ -e u

username enumeration

I got my username.

found username

In this final stage, we will execute a brute-force attack on the WordPress site to find passwords. We will use a custom wordlist. If you have no mind, that how to create a custom wordlist. You can visit my YouTube channel.

wpscan –url http://vtcsec/secret/ -U admin -P /usr/share/wordlists/rockyout.txt

Brute-Force Attack

In the end, we got the username and password.

Found Username : Password

We succeed. At this time, we will open the WordPress login page and login with an authenticate credential.

Login WordPress

Login using username: admin and password: admin and you can access dashboard admin. If you liked this blog, then you must subscribe to our YouTube channel.

WordPress Dashbord


Trending
Protected: How To Mount USB Drive in Ubuntu Linux

⭐⭐⭐⭐⭐

Rating: 5 out of 5.

Recent Posts


  • Protected: How To Mount USB Drive in Ubuntu Linux
  • CVE-2022-30190 (Follina)-Microsoft Support Diagnostic Tool Vulnerability
  • SQL INJECTION – Extracting Username and Password From Database
  • How To Dump Username And Password Using SQLMap Tool?
  • Protected: Exploit Apache Log4j Security Vulnerabilities – CVE-2021-44228

Most Popular Posts


  • Protected: How To Mount USB Drive in Ubuntu Linux
  • CVE-2022-30190 (Follina)-Microsoft Support Diagnostic Tool Vulnerability
  • SQL INJECTION – Extracting Username and Password From Database
  • How To Dump Username And Password Using SQLMap Tool?

Related

5 Comments

  1. Ryan Harish 09/09/2022

    The professional hacker true out the word that I believed in him is only Henryclarkethicalhacker Group Hackers Checked Google and see everybody comments on him he a professional that I believed in him if you have problems on any stuffed like a bank, company, school grades change examinations, database, Social media hacks, Email hacks, Phone hacks, Bitcoin hacks, increased Credit score boost to 800, School result upgrading, cryptocurrency, Binary option funds recovery, Bitcoin Mining, Instagram, WhatsApp, Twitter, Monitor your colleague, access your spouse social media, and a lot more, via, ,

    Reply
  2. Kate Lorena 05/02/2023

    Contact him for any type of hacking, he is a professional hacker that specializes in exposing cheating spouses, and every other hacking related issues. he is a cyber guru, he helps catch cheating spouses by hacking their communications like call, Facebook, text, emails, Skype, whats-app and many more. I have used this service before and he did a very good job, he gave me every proof I needed to know that my fiancee was cheating. You can contact him on his email to help you catch your cheating spouse, or for any other hacking related problems, like hacking websites, bank statement, grades and many more. he will definitely help you, he has helped a lot of people, contact him on, , and you can Text/Call &WhatsApp: +1 (773)-609-2741, or +1201-430-5865, and figure out your relationship status. I wish you the best.

    Reply
  3. Eliott Sharon 02/05/2023

    My girlfriend was very smart at hiding her infidelity from me due to some selfish reasons. So I had no proof for weeks while hurting myself during this process. Luckily I was referred to this private investigator and the result was awesome and top notch. All my girlfriend’s dirty chats, Facebook, WhatsApp, Instagram, and even phone conversations were directed to my cell phone, if your girlfriend, boyfriend, wife or husband are experts at hiding his or her cheating adventures, contact this fast and trusted link. You can reach them via, TEXT,Call & Whatsapp,+1(201)4305865, or +1(773)6092741…

    Reply
  4. Lizzy Agnes 24/09/2023

    A great hacker is really worthy of good recommendation , Henry
    really help to get all the evidence i needed against my husband and
    and i was able to confront him with this details from this great hacker
    to get an amazing service done with the help ,he is good with what he does and the charges are affordable, I think all I owe him is publicity for a great work done via, , and you can text, call him on whatsapp him on +12014305865, or +17736092741,

    Reply

Add a Comment

Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Protected: How To Mount USB Drive in Ubuntu Linux
  • CVE-2022-30190 (Follina)-Microsoft Support Diagnostic Tool Vulnerability
  • SQL INJECTION – Extracting Username and Password From Database
  • How To Dump Username And Password Using SQLMap Tool?
  • Protected: Exploit Apache Log4j Security Vulnerabilities – CVE-2021-44228

Recent Comments

  • Lizzy Agnes on How To Install AnyDesk In Ubuntu 20.04/18.04
  • Lizzy Agnes on Hack The Box (HTB) OSCP-Like machines List 2022
  • Lizzy Agnes on What is Termux? How To Use Termux Basic Command As a Beginner?
  • Lizzy Agnes on Download Our Best Hacking Videos Deleted by Youtube
  • Lizzy Agnes on Top 10 Best Computer Hacking Gadgets List 2022 For Hackers

Archives

  • January 2023
  • June 2022
  • May 2022
  • January 2022
  • December 2021
  • November 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021

Please Share

0
1
0
1
2
0
0
0
1

Follow Us

Pentestblog Youtube

RSS Pentestblog

  • Protected: How To Mount USB Drive in Ubuntu Linux

Categories

  • 0 Day CVE
  • 0-Day
  • Android Hacking
  • Apache Log4j
  • Blog
  • CTF Challange
  • CVE
  • Ethical Hacking
  • Gadgets
  • Hack the Box
  • Kali Linux
  • nothing
  • OSCP
  • Phishing
  • SQL Injeciton
  • SQL Injection
  • WordPress Hacking

Other Pages

  • Privacy Policy
  • DMCA
  • Terms and Conditions
  • About Us
  • Contact Us
  • Our Videos
  • Our Course
  • CTF Challenges
Pentestblog Copyright © 2024.
Created by Sandeep Yadav (Ethical Hacker) Back to Top ↑