Closed thepopol777 closed 11 years ago
WPScan is for self hosted WordPress blogs not WordPress hosted (SaaS) WordPress blogs (*.wordpress.com).
So thoses names are the names of the global owners of *.wordpress.com ?
I would think so, yea :)
maybe we can implement a warning with confirmation if the url is *.wordpress.com? Maybe there is also a way to detect wordpress.com blogs with own domains.
Yea, might be a good idea.
I guess our main 'target market' is pentesters and wordpress admins, the former should already know this but the later may not.
Hi everyone!
I'm running wpscan on kali linux. I'm only enumerating usernames, but whatever url I put, it always return the same users list O.o
For example, if I type:
wpscan --url http://test.wordpress.com --enumerate u
It returns admin, donncha, matt, 7 and ian.
Any ideas?