Domain Information
WordPress Version: 6.8.1 VULNERABLE
Theme: toyup (used by 17 domains)
Last Checked: 2026-09-08 04:55:05
HTTPS: Yes
Server: cloudflare
CDN / WAF: Cloudflare
Response time (TTFB): 137 ms fast
Hosting: Cloudflare, Inc. (AS13335)
IP address: 188.114.97.xxx
Plugins (16)
| Plugin | Used By |
|---|---|
| back-in-stock-notifier-for-woocommerce | 4,442 |
| cookie-notice | 143,167 |
| duracelltomi-google-tag-manager | 87,509 |
| elementor | 1,707,286 |
| facebook-for-woocommerce | 25,920 |
| fluentform | 57,134 |
| genel-shortcode-yazilimlari | 0 |
| grilabs-woocommerce-shipping | 0 |
| kutu-oyunu-kart-kilifi-ozellikleri | 0 |
| shopbuilder | 460 |
| shopbuilder-pro | 74 |
| user-registration | 2,852 |
| woo-product-bundle | 4,324 |
| woo-product-variation-gallery | 181 |
| woo-product-variation-swatches | 889 |
| woocommerce | 789,108 |
Security Headers
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.1) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- info.php exposed — Server configuration publicly visible ?
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (188.114.97.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- 0*1*9*2*3.xyz
- 0*1*5*5*5.xyz
- 0*9*a*e.link
- 0*5*3*2*7.xyz
- 0*b*a*m*v*e*.in
- 0*m*i.com
- 0*9*o*1.net
- 0*2*8*2*0*.com
- 0*3*.org
- 0*b*t*l*.com
- 0*b*t*u*.com
- 1*0*0*.uno
- 1*0*n*t*i*.com
- 1*0*i*d*n*s*a.net
- 1*0*e*d*r*h*p*n*t*t*t*.org
- 1*0*i*.bio
- 1*6*j*b*.net
- 1*7*r*v*m.com
- 1*b*s*c*s*n*d*a*s.c*.uk
- 1*c*i*-*n.net
- 1*2*e*p*.rs
- 1*2*a*t*m.org
- 1*0*h*t*o*g.com
- 1*1*n*t*o*e.com
- 1*3*.flights