Domain Information
WordPress Version: 6.9.4 VULNERABLE
Theme: ed-school (theme used by 310 domains)
Last Checked: 2026-08-03 02:20:03
HTTPS: Yes
Plugins (24)
| Plugin | Version | Used By |
|---|---|---|
| advanced-responsive-video-embedder | — | 5,223 |
| contact-form-7 | — | 1,699,668 |
| dflip | — | 4,962 |
| ed-school-plugin | — | 294 |
| elementor | — | 1,696,826 |
| elementor-pro | — | 1,010,880 |
| elfsight-instagram-feed-cc | — | 1,400 |
| eventon | — | 7,467 |
| eventon-weekly-view | — | 215 |
| gtranslate | — | 118,984 |
| js_composer | — | 402,159 |
| mega-submenu | — | 361 |
| mycred | — | 1,339 |
| mycred-learndash | — | 19 |
| powerpack-lite-for-elementor | — | 5,074 |
| redux-framework | — | 12,338 |
| revslider | — | 582,874 |
| sfwd-lms | — | 13,272 |
| testimonial-rotator | — | 4,608 |
| the-post-grid | — | 13,943 |
| widgetkit-for-elementor | — | 810 |
| woocommerce | — | 784,675 |
| wp-store-locator | — | 16,617 |
| youtube-gallery-vc | — | 205 |
Security Headers
D
Grade D
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.