id: wordpress-xmlrpc-listmethods info: name: Wordpress XML-RPC List System Methods author: 0ut0fb4nd severity: info metadata: max-request: 1 tags: wordpress,vuln http: - method: POST path: - "{{BaseURL}}/xmlrpc.php" body: "system.listMethods" matchers-condition: and matchers: - type: status status: - 200 - type: word words: - "system.multicall" - "system.listMethods" - "demo.sayHello" condition: and part: body # digest: 4a0a00473045022027141ae32337d30b3594b8f8c5c53f62312abb40d6142bbea8fcb64378988dd80221009c181a04c6c16cecdd4ff408658cabd5cabdf3dd108d4f2ad19b4c493af7b484:922c64590222798bb761d5b6d8e72950