# WPScan ## Themes ```sh wpscan --url --enumerate t ``` * `ls` for content ## Plugins ```sh wpscan --url --enumerate p ``` ## Users ```sh wpscan --url --enumerate u ``` ## Vulnerabilities * WPVulnDB API is needed * Plugins ```sh wpscan --url --enumerate vp ``` ## Password attack ```sh wpscan --url --passwords --usernames ``` ## WAF Aggressiveness ```sh wpscan --url --enumerate p --plugins-detection