Update database
wpscan --update
Scan installed plugins
wpscan --url http(s)://your-domain.com --enumerate p
Scan vulnerable plugins
wpscan --url http(s)://your-domain.com --enumerate vp
Scan installed themes
wpscan --url http(s)://your-domain.com --enumerate t
Scan vulnerable themes
wpscan --url http(s)://your-domain.com --enumerate vt
Scan user accounts:
wpscan --url http(s)://your-domain.com --enumerate u
Scan vulnerable timthumb files:
wpscan --url http(s)://your-domain.com --enumerate tt
Using WPVulnDB API
nano ~/.wpscan/scan.yml
Put the following lines in the file
cli_options:
api_token: YOUR_API_TOKEN