https://www.trendteam.eu
Scan complete
www.trendteam.eu
38 issues detected
Scanned 1 month ago
38
Total
0
Critical
7
High
17
Medium
WordPress version 6.1.1 detected
Plugin 'elementor' v3.7.8: Elementor <= 3.18.1 - Authenticated(Contributor+) Arbitrary File Upload to Remote Code Execution via Template Import
Plugin 'elementor' v3.7.8: Elementor <= 3.19.0 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization
Plugin 'elementor' v3.7.8: Elementor <= 3.12.1 - Authenticated(Administrator+) SQL Injection via 'replace_urls'
Plugin 'elementor' v3.7.8: Elementor Website Builder <= 3.16.4 - Missing Authorization to Arbitrary Attachment Read
Plugin 'elementor' v3.7.8: Elementor Website Builder <= 3.16.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()
Plugin 'autoptimize' v3.1.3: Multiple Plugins <= Multiple Versions - Unauthenticated Stored Cross-Site Scripting
Plugin 'autoptimize' v3.1.3: Autoptimize <= 3.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'autoptimize' v3.1.3: Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ao_post_preload' Meta Value
Plugin 'autoptimize' v3.1.3: Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy-loaded Image Attributes
Plugin 'woocommerce' v5.9.1: WooCommerce <= 6.2.0 - Path Traversal via Tax Importer
Plugin 'elementor-pro' v3.7.7: Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option
Plugin 'elementor-pro' v3.7.7: Elementor Website Builder <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'elementor-pro' v3.7.7: Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via video_html_tag
Plugin 'elementor-pro' v3.7.7: Elementor Website Builder Pro <= 3.20.1 - Authententicated (Contributor+) Stored Cross-Site Scripting
Plugin 'elementor-pro' v3.7.7: Elementor Website Builder Pro <= 3.21.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Plugin 'elementor-pro' v3.7.7: Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'elementor-pro' v3.7.7: Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Widget SVGZ File Upload
Plugin 'elementor-pro' v3.7.7: Elementor Pro <= 3.13.0 - Missing Authorization
WP_DEBUG is disabled (no PHP errors visible)
PHP 8.0.30 detected — end of life since Dec 2023
How to fix: Upgrade PHP to 8.2+ via your hosting control panel. Outdated PHP receives no security patches.
X-Powered-By header exposed: PHP/8.0.30 — reveals server software
How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
1 of 6 security headers configured
SSL certificate valid (80 days remaining) — issued by Sectigo Limited
HTTP correctly redirects to HTTPS
Debug log exposed
/wp-content/debug.log
WordPress readme exposed (version info)
/readme.html
WordPress license file exposed
/license.txt
User enumeration possible via REST API -- found: hostmaster, trendteam_api, hostmastertrendteam
How to fix: Disable the REST API users endpoint with a plugin like Disable REST API or add a filter to block /wp/v2/users.
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
Suspicious inline JavaScript: String.fromCharCode obfuscation
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
No external scripts detected
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49