Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: accalia-child
Last Checked: 2026-07-11 23:56:01
HTTPS: Yes
Plugins (26)
| Plugin | Used By |
|---|---|
| before-after-images | 0 |
| booked | 9,251 |
| contact-form-7 | 1,750,946 |
| cost-of-goods | 37 |
| email-verification-for-contact-form-7 | 229 |
| essential-grid | 34,906 |
| jetpack | 454,422 |
| js_composer | 419,728 |
| loyalty-program | 0 |
| membership-for-woocommerce | 80 |
| miniorange-login-openid | 1,915 |
| multi-select-provider | 0 |
| provider-notes | 0 |
| rateyourappointment | 0 |
| revslider | 608,520 |
| snazzy-maps | 4,813 |
| sticky-buttons | 1,333 |
| templumaw-sqaure-getway | 0 |
| the-events-calendar | 122,290 |
| trx_addons | 22,225 |
| user-registration | 3,701 |
| vc-extensions-bundle | 5,156 |
| woocommerce | 816,497 |
| woosquare | 185 |
| wp-expand-tabs-free | 1,651 |
| wp-logo-showcase-responsive-slider-slider | 6,656 |
Security Headers
C
Grade C
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.