Domain Information
WordPress Version: 6.9 VULNERABLE
Theme: jkc-v2
Last Checked: 2026-08-18 22:59:10
HTTPS: Yes
Plugins (22)
| Plugin | Used By |
|---|---|
| advanced-custom-fields | 967 |
| facetwp | 2,878 |
| facetwp-flyout | 192 |
| facetwp-submit | 464 |
| facetwp-time-since | 0 |
| gutenberg | 150,491 |
| if-menu | 9,542 |
| jkc-admin-custom-scripts | 0 |
| jkc-facetwp | 0 |
| jkc-facetwp-relationship | 0 |
| jkc-hello | 0 |
| jkc-hyperaudio | 0 |
| jkc-pmpro | 0 |
| jkc-powerpress | 0 |
| jkc-search-filter-pro | 0 |
| jkc-template-part-shortcode | 0 |
| jkc-utilities | 0 |
| myfontswebfontskit | 405 |
| paid-memberships-pro | 9,782 |
| search-filter-pro | 22,791 |
| wp-discourse | 114 |
| wp-hyperaudio | 7 |
Security Headers
D
Grade D
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.