CMS-Specific Scanning
Once tech fingerprinting (or HTML inspection) confirms a CMS, switch from generic discovery to CMS-aware tooling — version, plugins/themes, user enum, and CMS-specific RCE entry points.
WordPress
# wpscan (comprehensive)
wpscan --url https://<target> --enumerate vp,vt,u,be --api-token <WP_API_TOKEN>
# Quick checks
curl -s "https://<target>/wp-json/wp/v2/users" | python3 -m json.tool
curl -s "https://<target>/xmlrpc.php" -d '<methodCall><methodName>system.listMethods</methodName></methodCall>'
curl -s "https://<target>/?author=1" -I | grep Location
Joomla
# Version detection
curl -s "https://<target>/administrator/manifests/files/joomla.xml" | grep -oP '<version>\K[^<]+'
Drupal
curl -s "https://<target>/CHANGELOG.txt" | head -5