Create WordPress-user-registration-enabled.yaml
Description : Your WordPress site is currently configured so that anyone can register as a user. If you are not using this functionality, it's recommended to disable user registration as it caused some security issues in the past and is increasing the attack surface.patch-1
parent
741d05a4c0
commit
b4989107e6
|
@ -0,0 +1,21 @@
|
|||
id: WordPress user registration enabled
|
||||
|
||||
info:
|
||||
name: WordPress user registration enabled
|
||||
author: Ratnadip Gajbhiye
|
||||
severity: Medium
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
path:
|
||||
- '{{BaseURL}}/wp-login.php?action=register'
|
||||
matchers-condition: and
|
||||
matchers:
|
||||
- type: word
|
||||
words:
|
||||
- Register For This Site
|
||||
- E-mail
|
||||
part: body
|
||||
- type: status
|
||||
status:
|
||||
- 200
|
Loading…
Reference in New Issue