Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: bb-theme (used by 53,306 domains)
Last Checked: 2026-07-04 12:02:51
HTTPS: Yes
Plugins (12)
| Plugin | Used By |
|---|---|
| bb-plugin | 86,765 |
| bb-ultimate-addon | 19,611 |
| bbpowerpack | 39,919 |
| better-click-to-tweet | 2,607 |
| google-site-kit | 232,691 |
| mailchimp-for-wp | 81,620 |
| meks-smart-author-widget | 3,299 |
| page-links-to | 57,955 |
| popup-maker | 109,493 |
| tablepress | 102,356 |
| types | 4,099 |
| yoko-extend | 51 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.