Security Scan Results

https://esp2000.ro

Screenshot of https://esp2000.ro

esp2000.ro

F

Critical — Immediate Action Needed

26 issues detected

Scanned 3 weeks ago

26

Total

1

Critical

6

High

9

Medium

Medium

Plugin 'contact-form-7' v5.9.6: Contact Form 7 <= 6.0.5 - Order Replay Vulnerability

Medium

Plugin 'penci-review' v3.2.1: Penci Review <= 3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Medium

Plugin 'penci-recipe' v3.5: Penci Recipe <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Medium

Plugin 'penci-recipe' v3.5: Penci Recipe <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Medium

Plugin 'penci-portfolio' v1.0: Penci Portfolio <= 3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

High

Theme 'soledad' v8.5.2: Soledad < = 8.6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

High

Theme 'soledad' v8.5.2: Soledad <= 8.6.7 - Authenticated (Contributor+) Local File Inclusion via 'header_layout'

High

Theme 'soledad' v8.5.2: Soledad <= 8.5.9 - Unauthenticated Limited Local File Inclusion

High

Theme 'soledad' v8.5.2: Soledad <= 8.6.8 - Authenticated (Contributor+) Local File Inclusion

High

Theme 'soledad' v8.5.2: Soledad <= 8.7.0 - Authenticated (Contributor+) Local File Inclusion

High

Theme 'soledad' v8.5.2: Soledad <= 8.6.7 - Unauthenticated Arbitrary Shortcode Execution

Medium

Theme 'soledad' v8.5.2: Soledad <= 8.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pcsml_smartlists_h'

Info

WP_DEBUG is disabled (no PHP errors visible)

Medium

Missing security header: X-Frame-Options -- Prevents clickjacking attacks

How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.

Medium

Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing

How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.

Medium

Missing security header: Strict-Transport-Security -- Enforces HTTPS connections

How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

Info

Missing security header: Content-Security-Policy -- Controls resource loading

Info

Missing security header: Referrer-Policy -- Controls referrer information

Info

Missing security header: Permissions-Policy -- Controls browser feature access

Info

SSL certificate valid (54 days remaining) — issued by Let's Encrypt

Info

HTTP correctly redirects to HTTPS

Info

WordPress license file exposed

/license.txt

Info

REST API user enumeration blocked

Low

wp-cron.php is publicly accessible (potential DDoS vector)

/wp-cron.php

How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.

Info

No external scripts detected

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

How to fix: Your site is flagged as malicious. Request a review at Google Search Console after cleaning up.

Your site needs immediate attention

We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.

Get Expert Cleanup — $49
Scan another site