_______________________________________________________________ __ _______ _____ \ \ / / __ \ / ____| \ \ /\ / /| |__) | (___ ___ __ _ _ __ \ \/ \/ / | ___/ \___ \ / __|/ _` | '_ \ \ /\ / | | ____) | (__| (_| | | | | \/ \/ |_| |_____/ \___|\__,_|_| |_| WordPress Security Scanner by the WPScan Team Version 2.9 Sponsored by Sucuri - https://sucuri.net @_WPScan_, @ethicalhack3r, @erwan_lr, pvdl, @_FireFart_ _______________________________________________________________ The plugins directory 'wp-content/plugins' does not exist. You can specify one per command line option (don't forget to include the wp-content directory if needed) [?] Continue? [Y]es [N]o, default: [N] Y [+] URL: https://www.dfri.se/ [+] Started: Wed Nov 25 17:51:20 2015 [+] robots.txt available under: 'https://www.dfri.se/robots.txt' [!] The WordPress 'https://www.dfri.se/readme.html' file exists exposing a version number [!] Full Path Disclosure (FPD) in 'https://www.dfri.se/wp-includes/rss-functions.php': [+] Interesting header: SERVER: lighttpd/1.4.37 [+] Interesting header: STRICT-TRANSPORT-SECURITY: max-age=26280000 [+] Interesting header: X-POWERED-BY: PHP/5.5.30 [!] Registration is enabled: https://www.dfri.se/wp-login.php?action=register [+] XML-RPC Interface available under: https://www.dfri.se/xmlrpc.php [+] WordPress version 4.3.1 identified from stylesheets numbers [+] Enumerating plugins from passive detection ... | 2 plugins found: [+] Name: qtranslate-x - v3.4.6.4 | Latest version: 3.4.6.4 (up to date) | Location: https://www.dfri.se/wp-content/plugins/qtranslate-x/ | Readme: https://www.dfri.se/wp-content/plugins/qtranslate-x/readme.txt [+] Name: social - v3.1.1 | Latest version: 3.1.1 (up to date) | Location: https://www.dfri.se/wp-content/plugins/social/ | Readme: https://www.dfri.se/wp-content/plugins/social/README.txt