Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: kadence (used by 78,365 domains)
Last Checked: 2026-07-02 00:39:39
HTTPS: Yes
Plugins (19)
| Plugin | Used By |
|---|---|
| 3d-flipbook-dflip-lite | 43,851 |
| business-reviews-bundle | 12,829 |
| complianz-gdpr-premium | 37,799 |
| duracelltomi-google-tag-manager | 90,352 |
| kadence-blocks | 64,458 |
| kadence-blocks-pro | 18,868 |
| kadence-pro | 14,698 |
| kadence-related-content | 305 |
| kadence-shop-kit | 386 |
| mailchimp-for-woocommerce | 46,111 |
| recipe-card-blocks-by-wpzoom-pro | 262 |
| tablepress | 102,306 |
| wb-paytrail-maksutavat | 35 |
| weglot | 15,972 |
| woo-carrier-agents | 430 |
| woo-conditional-shipping-pro | 866 |
| woocommerce | 816,325 |
| woocommerce-gateway-stripe | 79,255 |
| woocommerce-multi-currency | 2,647 |
Security Headers
C
Grade C
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.