Domain Information
WordPress Version: 6.8.1 VULNERABLE
Theme: restored316-sprinkle-pro (theme used by 75 domains)
Last Checked: 2026-08-17 14:30:39
HTTPS: Yes
Plugins (14)
| Plugin | Version | Used By |
|---|---|---|
| convertkit | — | 14,005 |
| custom-facebook-feed | — | 39,717 |
| instagram-feed | — | 216,550 |
| ml-slider | — | 81,578 |
| pinterest-rss-widget | — | 713 |
| popupally | — | 414 |
| product-carousel-slider-for-woocommerce | — | 285 |
| simple-social-icons | — | 34,515 |
| social-warfare | — | 6,421 |
| woocommerce | — | 784,675 |
| woocommerce-menu-bar-cart | — | 13,096 |
| woocommerce-product-bundles | — | 8,219 |
| woocommerce-product-faq-manager | — | 33 |
| wpfm-faq-collector-addon | — | 10 |
Security Headers
D
Grade D
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.1) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.