Domain Information
WordPress Version: 6.9 VULNERABLE
Theme: dt-the7-child (theme used by 743 domains)
Last Checked: 2026-09-07 07:03:36
HTTPS: Yes
Server: Apache
Response time (TTFB): 937 ms
Hosting: Microsoft Corporation (AS8075)
IP address: 20.151.71.xxx
Plugins (13)
| Plugin | Version | Used By |
|---|---|---|
| contact-form-7 | — | 1,698,348 |
| dt-the7-core | — | 25,691 |
| easy-sticky-sidebar | — | 382 |
| js_composer | — | 401,781 |
| megamenu | — | 77,204 |
| megamenu-pro | — | 17,627 |
| page-scroll-to-id | — | 27,664 |
| revslider | — | 582,336 |
| snazzy-maps | — | 4,568 |
| super-socializer | — | 4,055 |
| ultimate_vc_addons | — | 53,141 |
| wordpress-cta-pro | — | 26 |
| wp-google-maps | — | 23,001 |
Security Headers
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.