Site Information
WordPress Version: 7.0 VULNERABLE
Theme: elessi-theme (used by 1,304 domains)
Last Checked: 2026-07-14 16:13:40
HTTPS: Yes
Plugins (19)
| Plugin | Used By |
|---|---|
| codecanyon-xsldxoc0-woocommerce-name-your-price-product-open-pricing | 0 |
| contact-form-7 | 1,726,397 |
| duracelltomi-google-tag-manager | 88,731 |
| essential-grid-3 | 37 |
| honeypot | 96,878 |
| improved-sale-badges | 184 |
| jetpack | 445,014 |
| js_composer | 409,969 |
| nasa-core | 1,335 |
| newsletter | 46,170 |
| nextend-smart-slider3-pro | 21,624 |
| stitch-express | 41 |
| twb-woocommerce-reviews | 128 |
| woocommerce | 802,542 |
| woocommerce-name-your-price | 3,187 |
| woocommerce-table-rate-shipping | 5,118 |
| woocommerce-twoship-rates | 0 |
| wp_estimation_form | 1,527 |
| wt-import-export-for-woo | 902 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.