Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: hestia (used by 12,423 domains)
Last Checked: 2026-08-15 10:51:07
HTTPS: No
Plugins (16)
| Plugin | Used By |
|---|---|
| contact-form-7 | 1,737,022 |
| cookie-notice | 146,452 |
| counter-number-showcase | 2,729 |
| elementor | 1,750,470 |
| elementor-pro | 1,042,074 |
| otter-blocks | 14,450 |
| pdf-embedder | 14,299 |
| tablesome | 989 |
| themeisle-companion | 10,407 |
| two-panel-file-manager | 0 |
| ultimate-social-media-icons | 26,193 |
| views-for-wpforms-lite | 245 |
| visitors-traffic-real-time-statistics | 4,811 |
| wpforms | 54,061 |
| wti-like-post | 457 |
| yop-poll | 1,475 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.