Site Information
WordPress Version: 6.8.3 VULNERABLE
Theme: tutorstarter (used by 561 domains)
Last Checked: 2026-07-16 22:21:02
HTTPS: Yes
Plugins (21)
| Plugin | Used By |
|---|---|
| 3d-flipbook-dflip-lite | 43,330 |
| bbpress | 13,426 |
| contact-form-7 | 1,726,397 |
| cookie-notice | 145,209 |
| country-phone-field-contact-form-7 | 7,634 |
| elementor | 1,737,471 |
| elementor-pro | 1,034,575 |
| ht-newsletter-for-elementor | 116 |
| jetsticky-for-elementor | 3,577 |
| kkiapay-woocommerce | 10 |
| lesson-bookmark-tutor-lms | 13 |
| mailchimp-for-wp | 79,286 |
| miniorange-otp-verification | 556 |
| paid-memberships-pro | 9,846 |
| subscriptions-for-woocommerce | 419 |
| the-events-calendar | 120,894 |
| tutor | 7,550 |
| tutor-pro | 3,432 |
| video-conferencing-with-zoom-api | 2,078 |
| woocommerce | 802,542 |
| woocommerce-multilingual | 25,970 |
Security Headers
D
Grade D
4 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.3) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.