Skip to content

Releases: wpscanteam/wpscan

v3.4.5

10 Mar 11:03
Compare
Choose a tag to compare
  • Adds detection of wp-cron.php - #1299
  • Handles uncaught exceptions when --password-attack was used but the XML-RPC was not detected - #1307
  • Improves Debug Log and XML-RPC detections (via CMSSCanner 0.0.41.4)

v3.4.4

11 Feb 12:11
Compare
Choose a tag to compare
  • Display enumeration methods (passive/aggressive) in output. (#1284)
  • Improves WordPress detection when no clues are present in the homepage (#1277)
  • Check for multi page results when gathering users via the WP JSON API (#1285 - Thanks to @melalj)

v3.4.3

11 Jan 13:18
Compare
Choose a tag to compare
  • Updates dependencies and specs

v3.4.1

13 Dec 22:42
Compare
Choose a tag to compare

Fixes #1264

v3.4.0

12 Nov 16:40
Compare
Choose a tag to compare

Fixes #1246
Fixes #1245
Fixes #1242
Fixes #1244
Fixes #1241

v3.3.3

02 Nov 21:30
Compare
Choose a tag to compare

Fixes #1228
Fixes #1232
Fixes #1236
Fixes #1237

v3.3.2

20 Oct 14:01
Compare
Choose a tag to compare
  • Adds a --hh cli option to display the full help. -h now displays a simplified help.

  • Displays the release date of the WP version detected.

v3.3.1

28 Sep 10:46
Compare
Choose a tag to compare

Fixes #1215

3.3.0

26 Sep 19:44
Compare
Choose a tag to compare

v3.x is a brand new codebase with many new features and enhancements.

2.9.4

15 Jun 08:37
Compare
Choose a tag to compare

Released: 2018-06-15

  • Updated dependencies and required ruby version
  • Improved CLI output
  • Only show readme.html output when wp <= 4.8 #1127
  • Cleanup README.md
  • Fix bug "undefined method 'identifier' for nil:NilClass" #1149
  • Since WP 4.7 readme.html only shows major version #1152
  • Add checks for humans.txt and security.text (Thank you @g0tmi1k!)
  • Add offline database update support (Thank you @g0tmi1k!)
  • Check for API access and /wp-json/'s users output (Thank you @g0tmi1k!)
  • Add RSS author information (Thank you @g0tmi1k!)
  • Check HTTP status of each value in /robots.txt (Thank you @g0tmi1k!)
  • Follow any redirections (e.g. http -> https) (Thank you @g0tmi1k!)
  • Lots of other enhancements by @g0tmi1k & WPScan Team
  • Database export file enumeration.

WPScan Database Statistics:

  • Total tracked wordpresses: 319
  • Total tracked plugins: 74896
  • Total tracked themes: 16666
  • Total vulnerable wordpresses: 305
  • Total vulnerable plugins: 1645
  • Total vulnerable themes: 286
  • Total wordpress vulnerabilities: 8327
  • Total plugin vulnerabilities: 2603
  • Total theme vulnerabilities: 352