I'd assume there's some basic attacks that could be performed in person since there's no ssl, but besides that, I'd assume the sites fairly secure if you use 2fa.
Ssh requires a decently long password or a certificate, and the admin panel requires you to log in again every time you go to it
Yeah that's pretty good, but there can be other things then just trying to break into the admin panel or break into another person's account. There could be Cross-Site Scripting attacks (XSS) CSRF attacks, SQL Injection, etc. Because there is no ssl, You could do a Man-In-The-Middle attacks, but that's only if someone was on your local network.
Since BitBuilt is using WordPress, you may have a vulnerable version or plugin. There are a whole bunch of things. If you want me to do some checking, I'd be more than happy too! I could write a report and PM it to you or however you want to receive it.