Information and communication and chemical technologies

No. 1 (26) - 2025 / 2025-03-31 / Number of views: 33

VULNERABILITY ANALYSIS OF WORDPRESS-BASED WEB APPLICATIONS USING WPSCAN

Authors

Karaganda Technical University named by Abylkas Saginov
https://orcid.org/0000-0003-3301-7282
Karaganda Technical University named by Abylkas Saginov
https://orcid.org/0009-0005-1037-0480
Karaganda Technical University named by Abylkas Saginov
https://orcid.org/0000-0002-6386-037X
Karaganda Technical University named by Abylkas Saginov
https://orcid.org/0000-0002-6232-1868
Karaganda Technical University named by Abylkas Saginov
https://orcid.org/0000-0001-7605-7634

Keywords

web Applications, Vulnerabilities, information security, data protection, attack, scanning, automated protection systems

Link to DOI:

https://doi.org/10.58805/kazutb.v.1.26-671

How to quote

G.T. Д., A.E. М. ., T.B. А., M.M. К., and Zh.Sailau kyzy С. к. “VULNERABILITY ANALYSIS OF WORDPRESS-BASED WEB APPLICATIONS USING WPSCAN”. Vestnik KazUTB, vol. 1, no. 26, Mar. 2025, doi:10.58805/kazutb.v.1.26-671.

Abstract

According to the growth of the Internet, the number of web applications, users and inexperienced developers, the problem of web application security remains relevant at all levels and requires a comprehensive approach. In this article the powerful web service scanning tool Wpscan is investigated. Examples of real vulnerabilities in the WordPress plugins and themes were considered. The plugins and themes are especially important for large web resources using many external modules. These examples show how important regular security updates and monitoring are to prevent threats. In this work, the site Sprut.ru was investigated for safety. Recommendations have also been developed to improve the security of the site. In particular, it is necessary to update the kernel version, remove or hide the file in the root directory, and regularly check the web resource for exploits.

Versions