ToolsWordPress Scanner
cmsSlow

WordPress Scanner

WordPress Vulnerability & Plugin Scanner

"CMS-specific vulnerability scanner — plugins, themes, users, and core vulnerabilities."

▶ Scan with WordPress Scanner
Overview

Content Management Systems power over 40% of all public websites. They are heavily targeted because of third-party plugin ecosystems. WordPress Scanner is Pentoolkit's dedicated CMS security engine with continuously updated vulnerability signatures.

PTK runs WordPress Scanner against installations to enumerate plugins, themes, active user accounts, and configuration issues. It cross-references installed components against known CVE databases. Three scan modes balance speed against depth.

Scan options
OptionDescriptionEst. time
light
Fast check — plugin list, obvious issues
~4 min/host
standardDEFAULT
Plugin + theme CVEs, user enumeration
~5 min/host
full
Aggressive plugin detection, all checks
~8 min/host
Example findings
CRITICALContact Form 7 5.3.1 — CVE-2021-39659 SQL Injection
HIGHXML-RPC Enabled — Brute Force Amplification Risk
HIGHWordPress 6.1.0 — 3 Known Vulnerabilities (update to 6.4.3)
MEDIUMreadme.html Exposed — WordPress Version Disclosed
What it discovers
  • Vulnerable WordPress plugins (CVEs with CVSS scores)
  • Vulnerable WordPress themes
  • Outdated WordPress core version
  • User enumeration via author pages
  • XML-RPC endpoint exposed (brute force amplification)
  • WordPress readme.html exposed (reveals exact version)
  • Upload directory listing enabled
  • Default admin username in use