My Journey to the CWES certification
🇲🇽 Lee este artículo en Español aquí.
My Journey to the CWES certification
🇲🇽 Lee este artículo en Español **aquí**.
Hi, I am Luis Eduardo Platero Fuentes (B13ss3d). On Wednesday, February 4th, 2026, I officially obtained the Certified Web Exploitation Specialist (CWES) certification.

Prerequisites & Cost 💵
To qualify for the exam, you must complete 100% of the Web Penetration Tester job-role path on the Academy.

Once completed, you can purchase the exam voucher for $210 USD, which remains valid for 360 days. While some consider this a foundational certification, I decided to pursue it to solidify my methodology and challenge my reporting skills (and yes, the Swag is a nice bonus!). To pass, you need a minimum of 80 out of 100 points (approximately 8 out of 10 flags).
The Exam Experience
After clicking “Enter Exam,” you are presented with the Terms & Conditions regarding confidentiality. We are then provided with a Letter of Engagement and a report template.
The Scenario: You receive a main domain scope. From there, you must enumerate to find 4 other hosts. Typically, there are 2 questions/flags per host.
Environment: The exam is accessible via VPN or the browser-based Pwnbox. You have 7 days to complete the exam and submit the report.
Key Technical Topics
While the entire learning path is valuable, I highly recommend focusing your review on:
- WordPress Exploitation (Plugin vulnerabilities).
- Vhost Discovery (Fuzzing is key).
- Verb Tampering (Bypassing restrictions).
My “Golden” Recommendations
1. Ditch the .docx Template, Use SysReptor The provided .docx template can be clunky. I strongly recommend using SysReptor. It is a valid option for this exam, much easier to manage, and ensures your final PDF stays under the 20 MB limit without formatting headaches.
2. Do NOT Underestimate the Report I learned this the hard way. Do not delay the reporting phase. I made the mistake of leaving documentation for the very last minute, which led to a fail on my first attempt and forced me to use a retake. Treat the report as part of the hack, not an afterthought.
3. Stuck? Go Back to Basics If you hit a wall during the exam, revisit the Academy modules. Pay close attention to the specific “Tips” sections in the course material, they often contain the subtle hints needed to solve the exam challenges.
Conclusion
Enjoy the process! The exam is genuinely fun. It is harder than the path, but it is completely solvable within the 7-day timeframe if you manage your time well.
If you are interested in cybersecurity, CTFs, and pentesting, I will be uploading related content and write-ups (of retired machines and public challenges) to my YouTube channel.
🎥 Subscribe here: B13ss3d Let’s Connect:
- LinkedIn: Luis Eduardo Platero Fuentes
- Twitter/X: @*B13ss3d*
Happy Hacking!
메타데이터
- post_id
- dd7e53c45bcb
- slug
- my-journey-to-the-cwes-certification-dd7e53c45bcb
- url
- https://medium.com/@bssd1358/my-journey-to-the-cwes-certification-dd7e53c45bcb
- canonical_url
- https://medium.com/@bssd1358/my-journey-to-the-cwes-certification-dd7e53c45bcb
- author_url
- https://medium.com/@bssd1358
- status
- ok
- fetched_at
- 2026-06-26 03:39:16