Black Box
- https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/wordpress
Obtaining Source Code
- Use WPScan to identify available plugins and then download them.
wp_ajax_nopriv_โ> Actions that are unauthenticatedadd_actionโ> WordPress actionswp_ajaxโ> AJAX functions
Paid WordPress plugins
- https://gemfury.com/jsarnowski (Includes Elementor Pro)
