Domain Information
WordPress Version: 6.8.1 VULNERABLE
Theme: hello-elementor (used by 606,018 domains)
Last Checked: 2026-07-22 17:17:26
HTTPS: Yes
Plugins (18)
| Plugin | Used By |
|---|---|
| elementor | 1,718,917 |
| elementor-pro | 1,024,573 |
| finale-woocommerce-sales-countdown-timer-discount | 427 |
| google-listings-and-ads | 24,516 |
| jet-blocks | 22,726 |
| jet-compare-wishlist | 1,492 |
| jet-elements | 63,339 |
| jet-engine | 76,204 |
| jet-reviews | 2,667 |
| jet-search | 16,194 |
| jet-tabs | 32,409 |
| jet-theme-core | 11,231 |
| jet-tricks | 21,662 |
| jet-woo-builder | 11,607 |
| jubelio-shipment | 13 |
| woo-custom-product-addons | 5,085 |
| woo-xendit-virtual-accounts | 333 |
| woocommerce | 794,091 |
Security Headers
D
Grade D
4 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.1) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.