What problem does it solve?
This Skill solves the critical problem of identifying and exploiting CORS misconfigurations on WordPress REST API endpoints, a high-severity vulnerability found in ~7-8% of US SMB WordPress sites that enables cross-origin credential theft and unauthorized data exfiltration.
Core Features & Use Cases
- 8 CORS Variant Detection: Identifies all 8 common CORS misconfiguration types, including origin reflection with credentials, null origin access, and plugin-specific CORS flaws.
- Exploit Validation & PoC Generation: Provides step-by-step procedures to confirm exploitability and build working browser proof-of-concept code for data exfiltration.
- Attack Chain Integration: Supports chaining CORS flaws with user enumeration and spear-phishing to achieve full WordPress admin account takeover. For penetration testers assessing WordPress site security, this Skill lets you quickly validate CORS findings, exfiltrate sensitive user and site data, and integrate the flaw into broader attack chains for full site compromise.
Quick Start
Use the cors-credential-wordpress skill to test a target WordPress site's REST API for exploitable CORS credential reflection vulnerabilities and generate a working browser proof-of-concept for sensitive data exfiltration.