Audit My WordPress Security of multiple websites.
Budget: €250 – €750 EUR
Evidence-Based WordPress Admin Access Assessment
I am looking for an experienced ethical hacker to perform a technical penetration test focused solely on the security of our WordPress admin backend.
The goal is to verify whether admin-level access can be obtained through real, demonstrable weaknesses.
This is not a general vulnerability audit and not a theoretical risk report.
Every finding must include evidence, otherwise it should not be reported as a weakness.
Objective
Evaluate whether unauthorised admin-level access to the WordPress backend is achievable via technical means.
If admin access is achieved, provide proof and detail the exact path used.
If admin access is NOT possible, confirm that the backend is secure against your attempted methods.
If a weakness is reported, it must be demonstrated, not guessed or assumed.
Scope of Testing (Technical Only)
You may investigate and attempt access through legitimate penetration-testing techniques, including:
Vulnerable or outdated plugins / themes
Outdated WordPress core
Misconfigurations in file permissions
Insecure endpoints, tokens, authentication flows
Weak or forgotten accounts (low-volume, rate-limited testing only)
Backdoors, leftover code, rogue cron jobs, or suspicious files
Server configuration or exposure issues that could lead to privilege escalation
Not permitted:
No social engineering
No high-volume brute force
No denial-of-service
No staff contact
Required Deliverables
1. Result Summary
State clearly whether admin access was achieved or not.
2. Evidence-Based Findings (Mandatory)
For every finding you report, you must include:
Screenshots or logs proving the behaviour described
Request/response samples or file paths accessed
Exact reproduction steps
Why the issue allowed access or could allow access
No evidence → the issue should not be listed as a confirmed vulnerability.
3. Proof of Admin Access (if successful)
If you gain admin access, provide:
Screenshots of the backend
Logs showing how the access was obtained
Detailed exploitation path and affected components
4. Hardening Recommendations
Clear instructions on how to resolve any demonstrated weaknesses.
5. Retest After Fixes
Once mitigations are applied, perform a retest to confirm that admin access is no longer possible.
I am looking for an experienced ethical hacker to perform a technical penetration test focused solely on the security of our WordPress admin backend.
The goal is to verify whether admin-level access can be obtained through real, demonstrable weaknesses.
This is not a general vulnerability audit and not a theoretical risk report.
Every finding must include evidence, otherwise it should not be reported as a weakness.
Objective
Evaluate whether unauthorised admin-level access to the WordPress backend is achievable via technical means.
If admin access is achieved, provide proof and detail the exact path used.
If admin access is NOT possible, confirm that the backend is secure against your attempted methods.
If a weakness is reported, it must be demonstrated, not guessed or assumed.
Scope of Testing (Technical Only)
You may investigate and attempt access through legitimate penetration-testing techniques, including:
Vulnerable or outdated plugins / themes
Outdated WordPress core
Misconfigurations in file permissions
Insecure endpoints, tokens, authentication flows
Weak or forgotten accounts (low-volume, rate-limited testing only)
Backdoors, leftover code, rogue cron jobs, or suspicious files
Server configuration or exposure issues that could lead to privilege escalation
Not permitted:
No social engineering
No high-volume brute force
No denial-of-service
No staff contact
Required Deliverables
1. Result Summary
State clearly whether admin access was achieved or not.
2. Evidence-Based Findings (Mandatory)
For every finding you report, you must include:
Screenshots or logs proving the behaviour described
Request/response samples or file paths accessed
Exact reproduction steps
Why the issue allowed access or could allow access
No evidence → the issue should not be listed as a confirmed vulnerability.
3. Proof of Admin Access (if successful)
If you gain admin access, provide:
Screenshots of the backend
Logs showing how the access was obtained
Detailed exploitation path and affected components
4. Hardening Recommendations
Clear instructions on how to resolve any demonstrated weaknesses.
5. Retest After Fixes
Once mitigations are applied, perform a retest to confirm that admin access is no longer possible.