https://www.eskabe.com.ar
Scan complete
47 issues detected
Scanned 2 weeks ago
47
Total
0
Critical
9
High
25
Medium
WordPress version 6.3.2 detected
Plugin 'woocommerce-mercadopago' v8.7.16: Mercado Pago payments for WooCommerce <= 8.9.0 - Unauthenticated Insecure Direct Object Reference
Plugin 'revslider' v6.4.6: Slider Revolution < 6.6.19 - Authenticated (Author+) PHP Object Injection
Plugin 'revslider' v6.4.6: Slider Revolution <= 6.6.15 - Authenticated (Author+) Arbitrary File Upload
Plugin 'revslider' v6.4.6: Slider Revolution <= 6.6.12 - Authenticated (Administrator+) Arbitrary File Upload
Plugin 'revslider' v6.4.6: Slider Revolution <= 6.7.37 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Read
Plugin 'revslider' v6.4.6: Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images'
Plugin 'woocustomizer' v2.6.3: StoreCustomizer – A plugin to Customize all WooCommerce Pages <= 2.6.3 - Missing Authorization
Plugin 'js_composer' v6.0.5: WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion
Plugin 'js_composer' v6.0.5: WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Heading tag attribute
Plugin 'js_composer' v6.0.5: WPBakery Page Builder <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements
Plugin 'js_composer' v6.0.5: WPBakery Page Builder for WordPress <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'js_composer' v6.0.5: WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Author
Plugin 'js_composer' v6.0.5: WPBakery Page Builder <= 8.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via Grid Builder
Plugin 'js_composer' v6.0.5: WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button onclick attribute
Plugin 'js_composer' v6.0.5: WPBakery Page Builder for WordPress <= 6.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'js_composer' v6.0.5: WPBakery <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting
Plugin 'cf7-conditional-fields' v2.6.4: Conditional Fields for Contact Form 7 <= 2.7.2 - Unauthenticated Denial of Service
Plugin 'contact-form-7' v5.9.8: Contact Form 7 <= 6.0.5 - Order Replay Vulnerability
Plugin 'woo-poly-integration' v1.5.0: Hyyan WooCommerce Polylang Integration <= 1.5.0 - Missing Authorization
Theme 'woodmart' v5.3.3: WoodMart <= 8.2.3 - Authenticated (Contributor+) Local File Inclusion
Theme 'woodmart' v5.3.3: Woodmart <= 8.3.8 - Unauthenticated PHP Object Injection
Theme 'woodmart' v5.3.3: WoodMart < 8.3.2 - Authenticated (Contributor+) Local File Inclusion
Theme 'woodmart' v5.3.3: Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution
Theme 'woodmart' v5.3.3: Woodmart <= 8.5.3 - Unauthenticated Stored Cross-Site Scripting
Theme 'woodmart' v5.3.3: Woodmart <= 7.1.1 - Cross-Site Request Forgery to License Update
Theme 'woodmart' v5.3.3: WoodMart <= 7.1.1 - Missing Authorization to Shortcode Injection
Theme 'woodmart' v5.3.3: WoodMart <= 8.0.3 - Unauthenticated Arbitrary Shortcode Execution
Theme 'woodmart' v5.3.3: WoodMart <= 8.3.7 - Unauthenticated Arbitrary Shortcode Execution
Theme 'woodmart' v5.3.3: WoodMart <= 8.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP_DEBUG is disabled (no PHP errors visible)
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
1 of 6 security headers configured
SSL certificate valid (88 days remaining) — issued by Let's Encrypt
HTTP correctly redirects to HTTPS
WordPress readme exposed (version info)
/readme.html
WordPress license file exposed
/license.txt
User enumeration possible via REST API -- found: abel, eskabeadmin, notideco_daeoax
How to fix: Disable the REST API users endpoint with a plugin like Disable REST API or add a filter to block /wp/v2/users.
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
Suspicious inline JavaScript: unescape() usage
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
Suspicious inline JavaScript: unescape() usage
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
3 trusted external script(s): stats.wp.com (WordPress), www.google.com (Google), www.googletagmanager.com (Google)
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49