Domain Information
WordPress Version: 6.9 VULNERABLE
Theme: jkc
Last Checked: 2026-08-15 13:01:18
HTTPS: Yes
Plugins (33)
| Plugin | Used By |
|---|---|
| cf7-conditional-fields | 33,154 |
| cf7-repeatable-fields | 1,296 |
| contact-form-7 | 1,707,342 |
| contact-form-7-multi-step-module | 9,071 |
| facetwp | 2,857 |
| facetwp-flyout | 192 |
| facetwp-time-since | 0 |
| hello-login | 0 |
| if-menu | 9,492 |
| jkc-admin-custom-scripts | 0 |
| jkc-discourse | 0 |
| jkc-facetwp | 0 |
| jkc-facetwp-relationship | 0 |
| jkc-hello | 0 |
| jkc-hum | 0 |
| jkc-hyperaudio | 0 |
| jkc-jquerymodal | 0 |
| jkc-placid | 0 |
| jkc-pmpro | 0 |
| jkc-powerpress | 0 |
| jkc-remotion | 0 |
| jkc-search-filter-pro | 0 |
| jkc-template-part-shortcode | 0 |
| jkc-utilities | 0 |
| mailchimp | 10,382 |
| mailchimp-for-wp | 77,749 |
| paid-memberships-pro | 9,731 |
| plausible-analytics | 2,228 |
| pmpro-mailchimp | 819 |
| powerpress | 2,174 |
| search-filter-pro | 22,619 |
| wp-discourse | 113 |
| wp-hyperaudio | 7 |
Security Headers
D
Grade D
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.