{"repo":"aashifm1/WordPress-BugBounty","free":true,"listed":false,"github":"https://github.com/aashifm1/WordPress-BugBounty","clone":"git clone https://github.com/aashifm1/WordPress-BugBounty.git","description":"It serves as a practical guide for security researchers to identify and test WordPress targets effectively during bug bounty hunting.","language":null,"stars":27,"topics":["bugbounty","pentesting","wordpress","wordpress-pentesting","wordpress-bugbounty"],"license":null,"category":"security-tools","readme_excerpt":"Wordpress (Bug-Bounty) For educational purposes only High-Impact Vulnerabilities 1. Plugin/Theme File Inclusion (LFI/RFI) 2. Insecure Direct Object References (IDOR) 3. SQL Injection (especially in custom plugins) 4. Arbitrary File Upload 5. Remote Code Execution (RCE) 6. Authentication Bypass 7. Privilege Escalation (Subscriber → Admin) 8. XXE/SSRF (often in import/export features) 9. Broken Access Control (WP REST API) 10. Unvalidated Redirects Common Attack Surfaces 1. REST API endpoints (/wp-json/ ) 2. Plugin AJAX handlers (wp-admin/admin-ajax.php) 3. File upload forms 4. Login/Registration endpoints 5. Comment functionality 6. Media library 7. Custom post types Medium Blogs 1. https://swapnilbodekar.medium.com/how-i-was-able-to-find-out-my-1st-cve-in-the-wordpress-plugin-fcbd524546fe 2. https://markazgasimov.medium.com/5-minutes-3-sites-1-wordpress-vulnerability-my-bug-bounty-win-9d4d90042833 3. https://medium.com/h7w/common-vulnerabilities-in-wordpress-sites-that-you-should-avoid-347c1f63d0c3 4. https://medium.com/legionhunters/zero-day-wordpress-plugin-vulnerability-research-275372d36781 5. https://bevijaygupta.medium.com/the-wordpress-bug-very-few-know-about-unveiling-a-lesser-known-security-flaw-0e333d518212 6. https://corneacristian.medium.com/top-25-wordpress-bug-bounty-reports-f208ea2dad3f 7. https://medium.com/@cuncis/a-beginners-guide-to-bug-hunting-and-exploiting-common-wordpress-vulnerabilities-821fe0d79461 8. https://medium.com/@niraj1mahajan/a-hackers-tale-f","default_branch":null,"files":null,"tree":[],"storefront":"/r/aashifm1","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/aashifm1/WordPress-BugBounty/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}