_______________________________________________________________
        __          _______   _____
        \ \        / /  __ \ / ____|
         \ \  /\  / /| |__) | (___   ___  __ _ _ __
          \ \/  \/ / |  ___/ \___ \ / __|/ _` | '_ \
           \  /\  /  | |     ____) | (__| (_| | | | |
            \/  \/   |_|    |_____/ \___|\__,_|_| |_|

        WordPress Security Scanner by the WPScan Team
                       Version 2.9
          Sponsored by Sucuri - https://sucuri.net
   @_WPScan_, @ethicalhack3r, @erwan_lr, pvdl, @_FireFart_
_______________________________________________________________

[+] URL: http://acme.fr/
[+] Started: Thu Dec 17 12:37:35 2015

[+] robots.txt available under: 'http://acme.fr/robots.txt'
[!] The WordPress 'http://acme.fr/readme.html' file exists exposing a version number
[!] Full Path Disclosure (FPD) in 'http://acme.fr/wp-includes/rss-functions.php': /home/acme/public_html/wp-includes/rss-functions.php
[+] Interesting header: LINK: <http://wp.me/P3TzhU-5r>; rel=shortlink, <http://acme.fr/wp-json>; rel="https://github.com/WP-API/WP-API"
[+] Interesting header: SERVER: Apache/2.4.7
[+] Interesting header: SET-COOKIE: wfvt_3710382548=56729f721ff5b; expires=Thu, 17-Dec-2015 12:11:38 GMT; Max-Age=1800; path=/; httponly
[+] Interesting header: X-POWERED-BY: PHP/5.5.9-1ubuntu4.14
[+] XML-RPC Interface available under: http://acme.fr/xmlrpc.php

[+] WordPress version 4.2.5 identified from stylesheets numbers

[+] WordPress theme in use: smartstart - v1.08

[+] Name: smartstart - v1.08
 |  Location: http://acme.fr/wp-content/themes/smartstart/
 |  Style URL: http://acme.fr/wp-content/themes/smartstart/style.css
 |  Theme Name: SmartStart WP - Responsive HTML5 Theme
 |  Theme URI: http://themeforest.net/user/smuliii/?ref=smuliii
 |  Description: SmartStart is a simple and clean but still professional template suitable for any business or por...
 |  Author: Samuli Saarinen
 |  Author URI: http://www.samuli.me/

[!] Title: Smart Start - VideoJS Cross-Site Scripting Vulnerability
    Reference: https://wpvulndb.com/vulnerabilities/7309
    Reference: http://seclists.org/fulldisclosure/2013/May/77
    Reference: https://secunia.com/advisories/53460/

[+] Enumerating plugins from passive detection ...
 | 4 plugins found:

[+] Name: contact-form-7 - v4.1.2
 |  Location: http://acme.fr/wp-content/plugins/contact-form-7/
 |  Readme: http://acme.fr/wp-content/plugins/contact-form-7/readme.txt
[!] The version is out of date, the latest version is 4.3.1

[+] Name: jetpack - v3.5.3
 |  Location: http://acme.fr/wp-content/plugins/jetpack/
 |  Readme: http://acme.fr/wp-content/plugins/jetpack/readme.txt
[!] The version is out of date, the latest version is 3.8.1

[!] Title: Jetpack <= 3.7.0 - Stored Cross-Site Scripting (XSS)
    Reference: https://wpvulndb.com/vulnerabilities/8201
    Reference: https://jetpack.me/2015/09/30/jetpack-3-7-1-and-3-7-2-security-and-maintenance-releases/
    Reference: https://blog.sucuri.net/2015/10/security-advisory-stored-xss-in-jetpack.html
[i] Fixed in: 3.7.1

[!] Title: Jetpack <= 3.7.0 - Information Disclosure
    Reference: https://wpvulndb.com/vulnerabilities/8202
    Reference: https://jetpack.me/2015/09/30/jetpack-3-7-1-and-3-7-2-security-and-maintenance-releases/
[i] Fixed in: 3.7.1

[+] Name: revslider
 |  Location: http://acme.fr/wp-content/plugins/revslider/

[!] We could not determine a version so all vulnerabilities are printed out

[!] Title: WordPress Slider Revolution Local File Disclosure
    Reference: https://wpvulndb.com/vulnerabilities/7540
    Reference: http://blog.sucuri.net/2014/09/slider-revolution-plugin-critical-vulnerability-being-exploited.html
    Reference: http://marketblog.envato.com/general/affected-themes/
    Reference: http://packetstormsecurity.com/files/129761/
    Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1579
    Reference: http://osvdb.org/show/osvdb/109645
    Reference: https://www.exploit-db.com/exploits/34511/
    Reference: https://www.exploit-db.com/exploits/36039/
[i] Fixed in: 4.1.5

[!] Title: WordPress Slider Revolution Shell Upload
    Reference: https://wpvulndb.com/vulnerabilities/7954
    Reference: https://whatisgon.wordpress.com/2014/11/30/another-revslider-vulnerability/
    Reference: http://osvdb.org/show/osvdb/115118
    Reference: https://www.rapid7.com/db/modules/exploit/unix/webapp/wp_revslider_upload_execute
    Reference: https://www.exploit-db.com/exploits/35385/
[i] Fixed in: 3.0.96

[+] Name: wp-google-maps - v6.1.7
 |  Location: http://acme.fr/wp-content/plugins/wp-google-maps/
 |  Readme: http://acme.fr/wp-content/plugins/wp-google-maps/readme.txt
[!] The version is out of date, the latest version is 6.3.03

[+] Finished: Thu Dec 17 12:37:44 2015
[+] Requests Done: 65
[+] Memory used: 144.055 MB
[+] Elapsed time: 00:00:09