Security Scan Results

https://www.trendteam.eu

Screenshot of https://www.trendteam.eu

www.trendteam.eu

F

Critical — Immediate Action Needed

38 issues detected

Scanned 1 month ago

38

Total

0

Critical

7

High

17

Medium

Info

WordPress version 6.1.1 detected

High

Plugin 'elementor' v3.7.8: Elementor <= 3.18.1 - Authenticated(Contributor+) Arbitrary File Upload to Remote Code Execution via Template Import

High

Plugin 'elementor' v3.7.8: Elementor <= 3.19.0 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization

Medium

Plugin 'elementor' v3.7.8: Elementor <= 3.12.1 - Authenticated(Administrator+) SQL Injection via 'replace_urls'

Medium

Plugin 'elementor' v3.7.8: Elementor Website Builder <= 3.16.4 - Missing Authorization to Arbitrary Attachment Read

Medium

Plugin 'elementor' v3.7.8: Elementor Website Builder <= 3.16.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()

High

Plugin 'autoptimize' v3.1.3: Multiple Plugins <= Multiple Versions - Unauthenticated Stored Cross-Site Scripting

Medium

Plugin 'autoptimize' v3.1.3: Autoptimize <= 3.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

Medium

Plugin 'autoptimize' v3.1.3: Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ao_post_preload' Meta Value

Medium

Plugin 'autoptimize' v3.1.3: Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy-loaded Image Attributes

High

Plugin 'woocommerce' v5.9.1: WooCommerce <= 6.2.0 - Path Traversal via Tax Importer

High

Plugin 'elementor-pro' v3.7.7: Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option

Medium

Plugin 'elementor-pro' v3.7.7: Elementor Website Builder <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Medium

Plugin 'elementor-pro' v3.7.7: Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via video_html_tag

Medium

Plugin 'elementor-pro' v3.7.7: Elementor Website Builder Pro <= 3.20.1 - Authententicated (Contributor+) Stored Cross-Site Scripting

Medium

Plugin 'elementor-pro' v3.7.7: Elementor Website Builder Pro <= 3.21.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

Medium

Plugin 'elementor-pro' v3.7.7: Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Medium

Plugin 'elementor-pro' v3.7.7: Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Widget SVGZ File Upload

Medium

Plugin 'elementor-pro' v3.7.7: Elementor Pro <= 3.13.0 - Missing Authorization

Info

WP_DEBUG is disabled (no PHP errors visible)

High

PHP 8.0.30 detected — end of life since Dec 2023

How to fix: Upgrade PHP to 8.2+ via your hosting control panel. Outdated PHP receives no security patches.

Low

X-Powered-By header exposed: PHP/8.0.30 — reveals server software

How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.

Medium

Missing security header: X-Frame-Options -- Prevents clickjacking attacks

How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.

Medium

Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing

How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.

Info

Missing security header: Content-Security-Policy -- Controls resource loading

Info

Missing security header: Referrer-Policy -- Controls referrer information

Info

Missing security header: Permissions-Policy -- Controls browser feature access

Info

1 of 6 security headers configured

Info

SSL certificate valid (80 days remaining) — issued by Sectigo Limited

Info

HTTP correctly redirects to HTTPS

High

Debug log exposed

/wp-content/debug.log

Info

WordPress readme exposed (version info)

/readme.html

Info

WordPress license file exposed

/license.txt

Medium

User enumeration possible via REST API -- found: hostmaster, trendteam_api, hostmastertrendteam

How to fix: Disable the REST API users endpoint with a plugin like Disable REST API or add a filter to block /wp/v2/users.

Low

wp-cron.php is publicly accessible (potential DDoS vector)

/wp-cron.php

How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.

Medium

Suspicious inline JavaScript: String.fromCharCode obfuscation

How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.

Info

No external scripts detected

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

Your site needs immediate attention

We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.

Get Expert Cleanup — $49
Scan another site