Domain Information
WordPress Version: 6.8.3 VULNERABLE
Theme: knowdadvisory 1.0· 100% conf.
Last Checked: 2026-09-09 10:47:27
HTTPS: Yes
Server: nginx
Response time (TTFB): 1,512 ms slow
Hosting: GMO Internet, Inc. (AS58791)
IP address: 157.120.209.xxx
Plugins (5)
| Plugin | Version | Used By |
|---|---|---|
| all-in-one-seo-pack | 4.9.1· 85% conf. | 84,026 |
| bogo | 3.7· 60% conf. | 2,842 |
| cf7-conditional-fields | 2.3.10· 85% conf. | 32,401 |
| contact-form-7 | 5.8· 85% conf. | 1,685,958 |
| contact-form-7-multi-step-module | 4.3.1· 85% conf. | 9,017 |
Security Headers
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.3) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (23)
These WordPress domains are served from the same IP (157.120.209.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*m*n*o*.com
- c*d*r*o*o*t*k*o*a.org
- d*r*-*i*i.com
- d*t*7*8.com
- d*t*m*u*r*a*.com
- d*e*-*a*t*n.com
- h*k*k*f*n*.com
- k*i*o*i*u*c*e.com
- k*r*-*i*i.com
- k*f*e*i*f*.com
- k*-*t*k*n*e*s*.com
- k*o*d*d*i*o*y.com
- k*s*n*t.com
- n*o*p.com
- o*a*a*i*p*a*o.com
- o*k*t*u*a*o*-*o*a.com
- p*t*e*a*s*.com
- r*e*l*.com
- r*x*y*-*e*s*n*l.com
- r*h*d*u*o*.com
- r*v*r*v*r*v*r.com
- s*o*t*c*-*s.com
- u*i*a*e.info