Hi, I’m doing a CTF on a WordPress site but WPscan shows no vulnerable plugins/themes. I have one username and wp-login page, but I’m told that brute-forcing is not required for this box. There aren’t any weird directories found via enumeration, and robots.txt only contains a line on wp-admin/admin-ajax.php.
In my experience with exploiting WordPress, usually finding something vulnerable in WPscan shows me which way to go, but now I’m stumped. Does anyone have any ideas, or is this a red herring?
submitted by /u/Slayre77
[link] [comments]