Scanning the *-bom.xml files in this repo directly with the CLI will give you a report in IQ. To work with the manual upload, the xml file(s) have to be in an archive (zip, tarball, etc) ...
With the use of this tool you will be able, given a username and a password dictionary, to bruteforce any given WordPress website through the use of its XML-RPC API. Disclaimer: For educational ...