Domain Information
WordPress Version: 7.0 VULNERABLE
Theme: nexproperty (theme used by 138 domains)
Last Checked: 2026-08-14 17:41:08
HTTPS: Yes
Plugins (28)
| Plugin | Version | Used By |
|---|---|---|
| elementinvader | — | 273 |
| elementinvader-addons-for-elementor | — | 271 |
| elementor | — | 1,695,155 |
| elementor-pro | — | 1,009,656 |
| gtranslate | — | 118,854 |
| header-footer-elementor | — | 195,990 |
| sep-file-manager | — | 5 |
| sweet-energy-efficiency | — | 10 |
| wdk-bookings | — | 9 |
| wdk-compare-listing | — | 6 |
| wdk-currency-conversion | — | 8 |
| wdk-duplicate-listing | — | 9 |
| wdk-facebook-comments | — | 5 |
| wdk-favorites | — | 9 |
| wdk-geo | — | 10 |
| wdk-listing-claim | — | 5 |
| wdk-mailchimp | — | 6 |
| wdk-membership | — | 14 |
| wdk-messages-chat | — | 6 |
| wdk-mortgage | — | 8 |
| wdk-pdf-export | — | 7 |
| wdk-report-abuse | — | 5 |
| wdk-reviews | — | 8 |
| wdk-save-search | — | 7 |
| wdk-svg-map | — | 9 |
| widget-detector-elementor | — | 477 |
| woocommerce | — | 783,975 |
| wpdirectorykit | — | 216 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.