Domain Information
WordPress Version: 7.0 VULNERABLE
Theme: g5plus-auteur (theme used by 280 domains)
Last Checked: 2026-07-25 07:39:23
HTTPS: Yes
Plugins (17)
| Plugin | Version | Used By |
|---|---|---|
| auteur-framework | — | 285 |
| book-previewer-for-woocommerce | — | 165 |
| elementor | — | 1,695,155 |
| elementor-pro | — | 1,009,656 |
| g5plus-post-like | — | 358 |
| jetpack | — | 405,557 |
| js_composer | — | 401,781 |
| post-and-page-builder | — | 6,923 |
| post-and-page-builder-premium | — | 4,904 |
| post-views-counter | — | 28,652 |
| revslider | — | 582,336 |
| socialfeeds | — | 1,019 |
| the-events-calendar | — | 117,844 |
| ultimate-bootstrap-elements-for-elementor | — | 668 |
| woocommerce | — | 783,975 |
| woocommerce-payments | — | 101,569 |
| woocommerce-paypal-payments | — | 33,766 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- phpinfo.php exposed — Server configuration publicly visible ?
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.