wordpress-penetration-testing
Originally fromzebbern/claude-code-guide
Installation
SKILL.md
AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.
WordPress Penetration Testing
WordPress 7.0 Security Considerations
WordPress 7.0 (April 2026) introduces new features that create additional attack surfaces:
Real-Time Collaboration (RTC)
- Yjs CRDT sync provider endpoints
wp_sync_storagepost meta- Collaboration session hijacking
- Data sync interception
AI Connector API
/wp-json/ai/v1/endpoints- Credential storage in Settings > Connectors
- Prompt injection vulnerabilities
- AI response manipulation