Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter
Burp WP - Find vulnerabilities in WordPress using Burp

22-01-2018 / Vulnerabilities

Burp WP - Find vulnerabilities in WordPress using Burp

Find known vulnerabilities in WordPress plugins and themes using Burp Suite proxy.

  • TL;DR: WPScan like plugin for Burp.

Install extension. Browse WordPress sites through Burp proxy. Vulnerable plugins and themes will appear on the issue list.

If you have Burp Pro, issues will also appear inside Scanner tab. Interesting things will be highlighted.

Timeline

  • 22-01-2018: Release

Vulnerabilities

Kallithea <= 0.3.4 Incorrect access control and XSS

This vulnerability allows a normal user to modify the permissions of repositories that he normally shouldn’t have access to.

12-12-2018

2 MIN READ

Vulnerabilities

Gitea 1.4.0 Unauthenticated Remote Code Execution

This is part 1 of 3 about bugs inside Gitea

05-07-2018

5 MIN READ

Vulnerabilities

ManageEngine Exchange Reporter Plus Unauthenticated Remote Code Execution

How to create a Metasploit module in example?

28-06-2018

1 MIN READ

© 2022 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter