[i] It seems like you have not updated the database for some time. [?] Do you want to update now? [Y]es [N]o [A]bort, default: [N]y [i] Updating the Database ... [i] Update completed. [+] URL: http://kuninganizer.com/ [+] Started: Tue Apr 25 10:30:04 2017 [+] robots.txt available under: 'http://kuninganizer.com/robots.txt' [+] Interesting entry from robots.txt: http://kuninganizer.com/wp-admin/admin-ajax.php [!] The WordPress 'http://kuninganizer.com/readme.html' file exists exposing a version number [+] Interesting header: AGE: 63 [+] Interesting header: SERVER: Rocket Booster [+] Interesting header: X-CACHE: HIT [+] Interesting header: X-CACHE-HITS: 2 [+] Interesting header: X-POWERED-BY: Warna Web Accelerator [+] Interesting header: X-VARNISH: 7379904 8230809 [+] XML-RPC Interface available under: http://kuninganizer.com/xmlrpc.php [+] WordPress version 4.7.4 (Released on 2017-04-20) identified from meta generator, links opml [+] WordPress theme in use: Newspaper - v7.8 [+] Name: Newspaper - v7.8 | Location: http://kuninganizer.com/wp-content/themes/Newspaper/ | Readme: http://kuninganizer.com/wp-content/themes/Newspaper/readme.txt | Style URL: http://kuninganizer.com/wp-content/themes/Newspaper/style.css | Theme Name: Newspaper | Theme URI: http://tagdiv.com | Description: Premium wordpress template, clean and easy to use. | Author: tagDiv | Author URI: http://themeforest.net/user/tagDiv/portfolio [+] Enumerating plugins from passive detection ... | 3 plugins found: [+] Name: google-captcha - v1.27 | Last updated: 2017-04-14T13:02:00.000Z | Location: http://kuninganizer.com/wp-content/plugins/google-captcha/ | Readme: http://kuninganizer.com/wp-content/plugins/google-captcha/readme.txt [!] The version is out of date, the latest version is 1.28 [!] Title: Multiple BestWebSoft Plugins - Authenticated Reflected GET Cross-Site Scripting (XSS) Reference: https://wpvulndb.com/vulnerabilities/8796 Reference: http://www.defensecode.com/advisories/DC-2017-02-014_50_WordPress_plugins_by_BestWebSoft_Advisory.pdf Reference: http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2017-April/010860.html [i] Fixed in: 1.28 [+] Name: js_composer | Location: http://kuninganizer.com/wp-content/plugins/js_composer/ [!] We could not determine a version so all vulnerabilities are printed out [!] Title: Visual Composer <= 4.7.3 - Multiple Unspecified Cross-Site Scripting (XSS) Reference: https://wpvulndb.com/vulnerabilities/8208 Reference: http://codecanyon.net/item/visual-composer-page-builder-for-wordpress/242431 Reference: https://forums.envato.com/t/visual-composer-security-vulnerability-fix/10494/7 [i] Fixed in: 4.7.4 [+] Name: wordpress-seo - v4.5 | Last updated: 2017-04-11T09:39:00.000Z | Location: http://kuninganizer.com/wp-content/plugins/wordpress-seo/ | Readme: http://kuninganizer.com/wp-content/plugins/wordpress-seo/readme.txt [!] The version is out of date, the latest version is 4.6 [+] Finished: Tue Apr 25 10:42:53 2017 [+] Requests Done: 104 [+] Memory used: 66.355 MB [+] Elapsed time: 00:12:49