WordPress
Malicious Plugin
Write a web shell with a malicious plugin.
Copy a plugin shell from SecLists and zip it:
Upload plugin-shell.zip
(Plugins > Add New) and install it (Upload Plugin > Browse... > Install Now) but do not activate! Now you can access the web shell:
wpscan
Last updated