https://github.com/wpscanteam/wpscan
Basis
wpscan --url [TARGET_IP] -e u,vp,vtScan Wordpress.
Flags
-e vpEnumerate Vulnerable Plugins.
-e vtEnumerate Vulnerable Themes.
-e cbEnumerate Config Backups.
-e dbeEnumerate DB Exports.
-e uEnumerate Users.
WPSCAN WordPress Login Brute Force
wpscan --url http://[TARGET_IP]/blog --usernames admin --passwords /usr/share/wordlists/rockyou.txtBrute force WordPress user's credentials.