Domain Information
WordPress Version: 6.9 VULNERABLE
Theme: xstore (theme used by 3,674 domains)
Last Checked: 2026-07-26 14:53:12
HTTPS: Yes
Plugins (15)
| Plugin | Version | Used By |
|---|---|---|
| advanced-dynamic-pricing-for-woocommerce | — | 3,920 |
| digits | — | 6,463 |
| elementor | — | 1,695,155 |
| et-core-plugin | — | 3,022 |
| free-shipping-label | — | 584 |
| jetpack | — | 405,557 |
| promote-mobile-app-on-website | — | 11 |
| woo-discount-rules | — | 16,886 |
| woo-product-bundle | — | 4,303 |
| woocommerce | — | 783,975 |
| woocommerce-points-and-rewards | — | 917 |
| wt-smart-coupons-for-woocommerce | — | 4,752 |
| yith-woocommerce-featured-video | — | 25 |
| yith-woocommerce-product-add-ons | — | 2,689 |
| yith-woocommerce-wishlist | — | 39,177 |
Security Headers
D
Grade D
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.