Attacking Common Applications - WordPress - Discovery & Enumeration

Just a hint to everyone… I feel like these HTB academy boxes can be quite unreliable at times. I discovered the “wp-sitemap-page” plugin through a hint on a page, but whenever I tried to open the plugins page, it threw an error 404… I restarted the machine and surprise, they page didn’t throw an error anymore

1 Like

Found the plugin and version. Had the same issue as many others. Thought the plugin was the one we get through manual and automated enumeration, but it’s not. Just try to enumerate a bit more but not exactly with your terminal… Once you find the plugin, you can navigate directly to the file containing important info.