Domain Information
WordPress Version: 6.9.1 VULNERABLE
Theme: materialcss (theme used by 16 domains)
Last Checked: 2026-08-20 08:09:49
HTTPS: Yes
Plugins (14)
| Plugin | Version | Used By |
|---|---|---|
| adrotate | — | 6,797 |
| bonoboslider | — | 21 |
| contact-form-7 | — | 1,698,348 |
| jquery-t-countdown-widget | — | 982 |
| newsletter | — | 44,987 |
| paid-memberships-pro | — | 9,671 |
| post-content-shortcodes | — | 549 |
| video-embed-thumbnail-generator | — | 2,950 |
| w3-total-cache | — | 37,577 |
| woocommerce | — | 783,975 |
| woocommerce-gateway-paypal-express-checkout | — | 7,963 |
| wootrello | — | 33 |
| wordpress-social-login | — | 1,883 |
| wp-post-to-trello-card | — | 0 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.