Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
WSS — Escáner de vulnerabilidades de WordPress de caja negra que detecta problemas de seguridad, enumera usuarios, fuerza bruta de inicios de sesión a través de XMLRPC y realiza análisis estático de código PHP para XSS y fallas de autorización. | Kitploit
Herramientas/GitHubGitHub/nu11secur1ty/wss
Escáneres de Vulnerabilidades WebAtaques de ContraseñasAnálisis de VulnerabilidadesAnálisis de CódigoRecopilación de InformaciónSeguridad Web
GitHubnu11secur1ty/wss

WSS

Escáner de vulnerabilidades de WordPress de caja negra que detecta problemas de seguridad, enumera usuarios, fuerza bruta de inicios de sesión a través de XMLRPC y realiza análisis estático de código PHP para XSS y fallas de autorización.

Ver Repositorio
3114hace 3 mesesAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

WSS: Escáner de seguridad de WordPress


Python: soporte

  • 3.13.x

Sistemas operativos: soporte

  • Kali Linux última versión
  • Ubuntu última versión
  • Windows 10, 11

WSS:En modo de desarrollo!!!

    • Google Dorks

¡ADVERTENCIA! ¡Cada acción maliciosa de tu parte será tu responsabilidad!

index of" inurl:wp-content/                      7,370,000 results 
inurl:"/wp-content/plugins/wp-shopping-cart/"    281,000 results
inurl:wp-content/plugins/wp-dbmanager/"          11,000 results

WSS es un escáner de vulnerabilidades de WordPress de caja negra que puede escanear instalaciones remotas de WordPress para encontrar problemas de seguridad. Se RECOMIENDA a todas las empresas que no pueden pagar profesionales de TI y expertos.

python license

screen_1

Instalación

$ git clone https://github.com/nu11secur1ty/WSS.git wss
$ cd wss
$ pip3 install -r requirements.txt
$ python wss.py

Uso

Escaneo genérico

python3 wss.py --url https://www.xxxxxxx.com --verbose

  • Salida
[ + ] Target: http://localhost/wordpress/
[ + ] Starting: 07:23:02

[ + ] Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
[ i ] Checking Full Path Disclosure...
[ i ] Checking wp-config backup file...
[ + ] wp-config.php available at: http://localhost/wordpress/wp-config.php
[ i ] Checking common files...
[ + ] LICENSE.txt file was found at: http://localhost/wordpress/LICENSE.txt
[ + ] readme.html file was found at: http://localhost/wordpress/readme.html
[ i ] Checking directory listing...
[ + ] Dir "/wp-admin/css" listing enable at: http://localhost/wordpress/wp-admin/css/
[ + ] Dir "/wp-admin/images" listing enable at: http://localhost/wordpress/wp-admin/images/
[ + ] Dir "/wp-admin/includes" listing enable at: http://localhost/wordpress/wp-admin/includes/
[ + ] Dir "/wp-admin/js" listing enable at: http://localhost/wordpress/wp-admin/js/
[ + ] Dir "/wp-content/uploads" listing enable at: http://localhost/wordpress/wp-content/uploads/
[ + ] Dir "/wp-includes/" listing enable at: http://localhost/wordpress/wp-includes/
[ + ] Dir "/wp-includes/js" listing enable at: http://localhost/wordpress/wp-includes/js/
[ + ] Dir "/wp-includes/Text" listing enable at: http://localhost/wordpress/wp-includes/Text/
[ + ] Dir "/wp-includes/css" listing enable at: http://localhost/wordpress/wp-includes/css/
[ + ] Dir "/wp-includes/images" listing enable at: http://localhost/wordpress/wp-includes/images/
[ + ] Dir "/wp-includes/pomo" listing enable at: http://localhost/wordpress/wp-includes/pomo/
[ + ] Dir "/wp-includes/theme-compat" listing enable at: http://localhost/wordpress/wp-includes/theme-compat/
[ i ] Checking wp-loging protection...
[ i ] Checking robots paths...
[ i ] Checking WordPress version...
[ + ] Running WordPress version: 6.7.1

[ i ] Passive enumeration themes...
[ + ] Name: twentytwentyfour
[ i ] Checking themes changelog...
[ i ] Checking themes full path disclosure...
[ i ] Checking themes license...
[ i ] Checking themes readme...
[ i ] Checking themes directory listing...
[ i ] Checking theme vulnerabilities...
  |   Not found vulnerabilities

[ i ] Passive enumeration plugins...
[ + ] Not found plugins with passive enumeration
[ i ] Enumerating users...
-------------------------
| ID | Username | Login |
-------------------------
|  0 | admin    | admin |
|  1 |          | admin |
-------------------------

Inicio de sesión por fuerza bruta

python3 wss.py --url https://www.xxxxxxx.com --brute --user test --wordlist wordlist.txt --verbose

  • Salida
$$       $$   $$$$$$    $$$$$$
$$   $   $$  $$    $$  $$    $$
$$  $$$  $$  $$        $$
$$ $$ $$ $$   $$$$$$    $$$$$$
$$$$   $$$$        $$        $$
$$$     $$$  $$    $$  $$    $$
$$       $$   $$$$$$    $$$$$$
v4.0

WSS - Wordpress Security Scanner
by nu11secur1ty


[ + ] Target: http://localhost/wordpress/
[ + ] Starting: 07:25:58

[ + ] Brute Forcing Login via XMLRPC...When you see any valid credentials press Ctrl + C to exit.
[ i ] Setting user: admin
[ + ] Valid Credentials:

-----------------------
| Username | Passowrd |
-----------------------
| admin    | password |
-----------------------

Escaneo de plugin, tema y código de WordPress

python3 wss.py --scan <dir/file> --verbose

Nota: Probando el plugin del directorio Akismet https://plugins.svn.wordpress.org/akismet

  • Salida
----------------------------------------
$$       $$   $$$$$$    $$$$$$
$$   $   $$  $$    $$  $$    $$
$$  $$$  $$  $$        $$
$$ $$ $$ $$   $$$$$$    $$$$$$
$$$$   $$$$        $$        $$
$$$     $$$  $$    $$  $$    $$
$$       $$   $$$$$$    $$$$$$
v4.0

WSS - Wordpress Security Scanner
by nu11secur1ty
----------------------------------------
Descargar herramienta