Domain Information
WordPress Version: 7.0 VULNERABLE
Theme: twentytwentyone (theme used by 28,756 domains)
Last Checked: 2026-07-22 23:22:00
HTTPS: Yes
Plugins (14)
| Plugin | Version | Used By |
|---|---|---|
| addon-elements-for-elementor-page-builder | — | 15,712 |
| call-to-action-block-wppool | — | 159 |
| easy-video-player | — | 6,167 |
| elementor | — | 1,689,719 |
| elementskit-lite | — | 169,378 |
| embed-pdf-viewer | — | 4,662 |
| essential-addons-for-elementor-lite | — | 250,728 |
| header-footer-elementor | — | 195,384 |
| jetpack | — | 402,304 |
| layout-grid | — | 6,448 |
| list-last-changes | — | 156 |
| master-addons | — | 3,312 |
| mojo-marketplace-wp-plugin | — | 18,118 |
| simple-blog-card | — | 464 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.