End goal is to be able to enumerate WordPress users on a site, using different techniques:
- JSON API - direct
- JSON API - circumvented
- Old-school URL structure enumeration
Usage:
-url string
WordPress URL. Required.
-enum int
Enumeration type. One of 0, 1 or 2:
0: JSON API, normal REST endpoint
1: JSON API, via GET query var
2: brute guessing via author param
-start int
Start enumeration at this user ID (default 1). Used with enum type 2.
-end int
End enumeration with this user ID (default 10). Used with enum type 2.
-pretty
Pretty-print the results
-ua
Randomize User-Agent
-cookies
Send mock WP cookies. Helps with some modsec rulesets (comodo WAF)
-waf
Attempt to work around a WAF (randomizes UA and sends mock WP cookies)