Site Information
WordPress Version: 6.8.3 VULNERABLE
Theme: the-portfolio-collective
Last Checked: 2026-07-20 03:46:41
HTTPS: Yes
Plugins (27)
| Plugin | Used By |
|---|---|
| bdthemes-element-pack-lite | 12,353 |
| buddypress-global-search | 189 |
| buddypress-learndash | 132 |
| cookie-notice | 146,603 |
| dynamicconditions | 18,129 |
| ele-custom-skin | 26,175 |
| elementor | 1,752,251 |
| elementor-pro | 1,042,958 |
| elementskit | 20,854 |
| elementskit-lite | 177,070 |
| essential-addons-for-elementor-lite | 261,374 |
| mec-shortcode-designer | 411 |
| mec-single-builder | 1,048 |
| memberpress | 7,303 |
| miniorange-login-openid | 1,897 |
| modern-events-calendar | 6,471 |
| sfwd-lms | 13,766 |
| the-portfolio-collective | 0 |
| tpc-automation | 0 |
| tpc-events | 0 |
| youzify | 644 |
| youzify-activity-reactions | 49 |
| youzify-block-members | 35 |
| youzify-edit-activity | 38 |
| youzify-membership-restrictions | 41 |
| youzify-moderation | 36 |
| youzify-social-share | 34 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.3) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.