A real audit of an SME WordPress site: Elementor pinned at 3.11.1 with four critical CVEs, and Contact Form 7 at 5.8 exposed to CVE-2023-6449 arbitrary file upload. The outdated-plugin pattern that fast and AI-assisted builds leave behind, and how an audit catches it.