Hacking WordPress with Kali and WPScan for Beginners

Опубликовано: 12 Май 2026
на канале: SYNACK Time
6,038
130

In this video, we discuss how to use WPScan, an open source utility that is provided to us free via Kali Linux. We will discuss what scan results look like, how to get the most out of the software and hack into a live WordPress site. This video is strictly for educational purposes.

⌚ Setting up the API with WPScan
⌚ Review the results with and without the API
⌚ Exploiting vulnerabilities of older WordPress versions
⌚ Examining vulnerable plugins
⌚ Brute force attacking accounts

I always enjoy learning about new cyber security programs even if they're for red teaming, sometimes especially if they're for red teaming! I hope this video encourages you to learn more! The things I discuss in this video are merely starting points and things you should think about when trying to gain access.

Chapters:
0:00 - Intro
1:00 - Finding help
2:05 - Getting a free API
3:38 - Scanning without the API
5:35 - Scanning with the API
5:48 - Robots.txt
6:35 - Vulnerabilities in WordPress
8:00 - Exploiting vulnerable files in WordPress
12:20 - Understanding the vulnerabilities in WordPress plugins
14:25 - Brute forcing accounts
17:40 - Summary


Resources:.
WPScan - https://wpscan.com
WPScan Cheat Sheet - https://wpscan.com/blog/wpscan-cli-ch...

SynAckTime - https://synacktime.com
Running Kali in VirtualBox -    • Running Kali Linux on VirtualBox