Word Press

Bruteforce directories:

gobuster dir -u http://target2.ine.local/wpcontent/plugins/ -w /usr/share/nmap/nselib/data/wp-plugins.lst

Enumerate:

wpscan

wpscan

Nikto

This shows plugins used and their sensitivity

nikto -h