{"repo":"Automattic/wpscan-vulnerability-test-bench","free":true,"listed":false,"github":"https://github.com/Automattic/wpscan-vulnerability-test-bench","clone":"git clone https://github.com/Automattic/wpscan-vulnerability-test-bench.git","description":"Standardised setup for researching WordPress plugin- and theme vulnerabilities.","language":"PHP","stars":32,"topics":["ddev","docker","vulnerability-assessment","vulnerability-research","wordpress"],"license":"GPL-2.0","category":"deployment-docker-iac","readme_excerpt":"WPScan Vulnerability Testbench A DDEV/docker based environment for exploring and replicating vulnerabilities in WordPress plugins and themes. Up and running See the DDEV installation instructions for how to install and set up docker and DDEV on your system. Clone this repo: Enter the test site directory and launch it: This should open the test site in your web browser, where you can install the plugin/theme you want to test as normal. Why? When evaluating potential vulnerabilities reported to WPScan, we see a number of common issues that makes it difficult to verify the reported vulnerability. Sometimes this is because the environment where the reported originally reproduced the issue is configured in a specific way. Also we do get a number of reported issues that does not properly consider the WordPress security model, like users with Administrator or Editor privileges being allowed to inject HTML and Javascript in places where it would normally not make sense to do so. To adress both of these issues, we decided we should try to supply a standardised environment so that issues can be reproduced reliably and in a known environment. Standard setup This DDEV environment will by default set up WordPress in a multisite configuration with one site at the root of the domain. It will create the following users: Username Description ---------- ------------- superadmin The superadmin with access to the full network simpleadmin Admin for the base site editor User with Editor role for t","default_branch":null,"files":null,"tree":[],"storefront":"/r/Automattic","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Automattic/wpscan-vulnerability-test-bench/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}