WordPress Stack Check
kohinoormills.com
Results Summary
40 findings detected across kohinoormills.com.
8 components identified. WordPress detected: Yes.
Severity Breakdown
Total findings detected across all components. The public summary below groups findings by vulnerability type. To see every affected component in full detail, run a free scan on your own domain at vulnify.app/tools.
Findings Overview
29 unique issues shown below, grouped from 40 total findings. When a vulnerability affects multiple components, it is listed once with the affected component count.
-
critical plugin: contact-form-7 has known vulnerability intelligence match
Affects 8 components
Detected version: 6.1.6 | Evidence quality: version-confirmed | Confidence score: 90 | Affected range: any to any | Patched version: true | CVE: n/a
CVE: CVE-2020-35489CVE-2018-20979CVE-2025-3247CVE-2023-6449CVE-2024-4704
-
high plugin: devvn-image-hotspot has known vulnerability intelligence match
Affects 2 components
Detected version: 6.1.6 | Evidence quality: version-confirmed | Confidence score: 90 | Affected range: any to any | Patched version: true | CVE: CVE-2024-7656
-
high Content-Security-Policy header missing
No CSP header detected. XSS impact surface is larger.
-
medium xmlrpc.php responded on the public WordPress surface
Observed xmlrpc.php status 403. Restrict or disable xmlrpc unless a business-critical workflow still requires it.
-
medium REST API user-related routes appear discoverable from wp-json output
The wp-json response referenced user endpoints. Review whether public user enumeration should be constrained on this site.
-
medium Public readme artifact disclosed WordPress core version evidence
GET /readme.html responded with status 200 and exposed WordPress version clue 2.
-
medium WordPress installation or upgrade surfaces responded publicly
HEAD /wp-admin/install.php -> 403; HEAD /wp-admin/upgrade.php -> 200.
-
medium Public plugin readme files confirmed additional version evidence
contact-form-7 v6.1.6, devvn-image-hotspot v1.3.0
-
medium plugin: oxygen has known vulnerability intelligence match
Detected version: 1.3.0 | Evidence quality: version-confirmed | Confidence score: 90 | Affected range: any to any | Patched version: true | CVE: CVE-2022-46841
CVE: CVE-2022-46841
-
medium plugin: cf7-conditional-fields has known vulnerability intelligence match
Affects 4 components
Detected version: 4.9.1 | Evidence quality: version-confirmed | Confidence score: 90 | Affected range: any to any | Patched version: true | CVE: CVE-2023-47838
-
medium Strict-Transport-Security (HSTS): missing
Ensures the browser only connects over HTTPS
-
medium Content-Security-Policy (CSP): missing
Prevents XSS and data injection attacks
-
medium X-Frame-Options: missing
Prevents clickjacking attacks
-
medium X-Content-Type-Options: missing
Prevents MIME-type sniffing
-
medium X-XSS-Protection: missing
Legacy XSS protection (modern browsers use CSP)
-
medium Referrer-Policy: missing
Controls how much referrer information is shared
-
medium Permissions-Policy: missing
Controls browser features and APIs
-
medium [REDACTED]: missing
Restricts Adobe Flash and PDF policies
-
medium Potentially sensitive paths are accessible
/admin (200, admin-surface, confidence:medium), /wp-admin (200, admin-surface, confidence:medium)
-
medium Administrative entry surfaces responded publicly
/admin (200), /wp-admin (200)
9 findings are grouped in this public summary
This public page groups findings by vulnerability type to avoid exposing sensitive configuration details about kohinoormills.com. To see the full breakdown including every affected component, version number, and remediation step, run a free scan on your own domain using Vulnify.
Run a Free Scan on kohinoormills.comWhat the WordPress Stack Check Covers
This security profile for kohinoormills.com was generated by Vulnify. The check analyzes:
- WordPress core version detection and known vulnerability lookup
- Active theme identification and security assessment
- Plugin inventory with version and CVE checks
- Security headers and hardening controls
- Exposed wp-config and sensitive file checks
- XML-RPC and REST API exposure assessment
Prioritized Actions
- highUpgrade vulnerable WordPress components
- highAdd Content-Security-Policy (CSP) header
- highAdd Strict-Transport-Security (HSTS) header
- highAdd baseline CSP
- highHarden cookies
- highRestrict sensitive paths
- highAdd edge-layer deny rules
- mediumRestrict or disable xmlrpc.php
- mediumReview REST API user exposure
- mediumRemove public WordPress version artifacts
- mediumConstrain public maintenance surfaces
- mediumAdd X-Frame-Options header
- mediumAdd X-Content-Type-Options header
- mediumAdd Referrer-Policy header
- mediumUse hardened cookie prefixes where possible
Run a Full Security Scan on kohinoormills.com
Check for XSS, SQL injection, CSRF, broken authentication, and 50+ additional security tests with a complete vulnerability assessment.
About This Check
This report was generated using Vulnify's free security tools. Results reflect the configuration at the time of the check. For ongoing monitoring, detailed remediation guidance, and vulnerability scanning across 50+ security tests, create a free Vulnify account.
Last checked:
Report abuse
If this page contains sensitive data, copyright issues, or should not be public, report it.