Domain Information
WordPress Version: 6.8.2 VULNERABLE
Theme: amaze (theme used by 9 domains)
Last Checked: 2026-08-24 11:06:30
HTTPS: Yes
Plugins (8)
| Plugin | Version | Used By |
|---|---|---|
| acf-layouts | — | 0 |
| favorites | — | 2,972 |
| frontend-reset-password | — | 2,212 |
| interactive-3d-flipbook-powered-physics-engine | — | 16,458 |
| interactive-geo-maps-premium | — | 936 |
| reports | — | 0 |
| video-contest | — | 35 |
| wordpress-social-login | — | 1,876 |
Security Headers
D
Grade D
4 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.2) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.