This Metasploit module attempts to find Wordpress credentials by abusing the XMLRPC APIs. Wordpress versions prior to 4.4.1 are suitable for this type of technique. For newer versions, the script will drop the CHUNKSIZE to 1 automatically.
86141a52d8d8035b170f6b501c77432e3aa0ad370de1b670688134dc56bcc34a
Client exec is billing software written in PHP. The installed base (and therefore impact of this) is very low. A default installation contains a phpinfo.php file in one of the mail directories.
16fc8530f38bf881e25e76744b3c227ce6b2c589e7b704278682ed95c62b7ce0