Site Information
WordPress Version: 6.8.2 VULNERABLE
Theme: blocksy (used by 50,105 domains)
Last Checked: 2026-08-18 17:59:42
HTTPS: Yes
Plugins (23)
| Plugin | Used By |
|---|---|
| advanced-coupons-for-woocommerce-free | 5,102 |
| advanced-dynamic-pricing-for-woocommerce | 3,994 |
| advanced-gift-cards-for-woocommerce | 140 |
| affiliate-and-referral-for-woocommerce | 25 |
| all-in-one-seo-pack | 86,705 |
| click-to-chat-for-whatsapp | 58,872 |
| easy-sale-badges-for-woocommerce | 708 |
| elementor | 1,737,471 |
| elementor-pro | 1,034,575 |
| flexible-shipping | 19,707 |
| gtranslate | 121,325 |
| klaviyo | 9,310 |
| loyalty-program-for-woocommerce | 193 |
| minmax-quantity-for-woocommerce | 2,993 |
| quick-buy-now-button-for-woocommerce | 524 |
| smartarget-viber-contact-us | 7 |
| woo-conditional-product-fees-for-checkout | 1,504 |
| woocommerce | 802,542 |
| woocommerce-catalog-enquiry | 412 |
| woocommerce-menu-bar-cart | 13,391 |
| woocommerce-photo-reviews | 957 |
| woocommerce-product-price-based-on-countries | 1,787 |
| wpdatatables | 7,164 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.2) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.