Audit My WordPress Security of multiple websites.

Job ID: 40042802

Budget: €250 – €750 EUR

Evidence-Based WordPress Admin Access Assessment

I am looking for an experienced ethical hacker to perform a technical penetration test focused solely on the security of our WordPress admin backend.
The goal is to verify whether admin-level access can be obtained through real, demonstrable weaknesses.

This is not a general vulnerability audit and not a theoretical risk report.
Every finding must include evidence, otherwise it should not be reported as a weakness.

Objective

Evaluate whether unauthorised admin-level access to the WordPress backend is achievable via technical means.

If admin access is achieved, provide proof and detail the exact path used.

If admin access is NOT possible, confirm that the backend is secure against your attempted methods.

If a weakness is reported, it must be demonstrated, not guessed or assumed.

Scope of Testing (Technical Only)

You may investigate and attempt access through legitimate penetration-testing techniques, including:

Vulnerable or outdated plugins / themes

Outdated WordPress core

Misconfigurations in file permissions

Insecure endpoints, tokens, authentication flows

Weak or forgotten accounts (low-volume, rate-limited testing only)

Backdoors, leftover code, rogue cron jobs, or suspicious files

Server configuration or exposure issues that could lead to privilege escalation

Not permitted:

No social engineering

No high-volume brute force

No denial-of-service

No staff contact

Required Deliverables
1. Result Summary

State clearly whether admin access was achieved or not.

2. Evidence-Based Findings (Mandatory)

For every finding you report, you must include:

Screenshots or logs proving the behaviour described

Request/response samples or file paths accessed

Exact reproduction steps

Why the issue allowed access or could allow access

No evidence → the issue should not be listed as a confirmed vulnerability.

3. Proof of Admin Access (if successful)

If you gain admin access, provide:

Screenshots of the backend

Logs showing how the access was obtained

Detailed exploitation path and affected components

4. Hardening Recommendations

Clear instructions on how to resolve any demonstrated weaknesses.

5. Retest After Fixes

Once mitigations are applied, perform a retest to confirm that admin access is no longer possible.