URL: https://www.lo3.lomza.pl/ [194.181.228.45] Started: Mon Apr 13 08:17:57 2026 Interesting Finding(s): Headers | Interesting Entries: | - Alt-Svc: h3=":60413"; ma=2592000,h3=":60414"; ma=2592000,h3=":60418"; ma=2592000 | - Server: BitNinja-Waf3, nginx | - X-Powered-By: PHP/7.4.26 | Found By: Headers (Passive Detection) | Confidence: 100% robots.txt found: https://www.lo3.lomza.pl/robots.txt | Interesting Entries: | - /wp-admin/ | - /wp-admin/admin-ajax.php | Found By: Robots Txt (Aggressive Detection) | Confidence: 100% XML-RPC seems to be enabled: https://www.lo3.lomza.pl/xmlrpc.php | Found By: Direct Access (Aggressive Detection) | Confidence: 100% | References: | - http://codex.wordpress.org/XML-RPC_Pingback_API | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/ | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/ WordPress readme found: https://www.lo3.lomza.pl/readme.html | Found By: Direct Access (Aggressive Detection) | Confidence: 100% The external WP-Cron seems to be enabled: https://www.lo3.lomza.pl/wp-cron.php | Found By: Direct Access (Aggressive Detection) | Confidence: 60% | References: | - https://www.iplocation.net/defend-wordpress-from-ddos | - https://github.com/wpscanteam/wpscan/issues/1299 WordPress version 6.3.1 identified (Insecure, released on 2023-08-29). | Found By: Emoji Settings (Passive Detection) | - https://www.lo3.lomza.pl/, Match: 'wp-includes\/js\/wp-emoji-release.min.js?ver=6.3.1' | Confirmed By: Meta Generator (Passive Detection) | - https://www.lo3.lomza.pl/, Match: 'WordPress 6.3.1' The main theme could not be detected. Enumerating Users (via Passive and Aggressive Methods) Brute Forcing Author IDs -: |=================================================| User(s) Identified: lo3lomza | Found By: Wp Json Api (Aggressive Detection) | - https://www.lo3.lomza.pl/wp-json/wp/v2/users/?per_page=100&page=1 | Confirmed By: | Rss Generator (Aggressive Detection) | Author Id Brute Forcing - Author Pattern (Aggressive Detection) No WPScan API Token given, as a result vulnerability data has not been output. You can get a free API token with 25 daily requests by registering at https://wpscan.com/register Finished: Mon Apr 13 08:18:21 2026 Requests Done: 76 Cached Requests: 64 Data Sent: 20.927 KB Data Received: 2.763 MB Memory used: 168.773 MB Elapsed time: 00:00:23