NewExtra server protection with Measured Boot & UKI images.View Measured Boot
BlogDocumentationFAQNo Third-Party CookiesContact Us
  • Pricing
Log inSign up
Cloud VPSVDSMemory-Optimized VDSStorage-Optimized VDSWindows VPSBitcoin VPSDDoS ProtectionPrivate Networking (VPC)Floating IPsAdditional Server SupportMicrosoft LicensesDatacenterNetworkDocumentationFAQNo Third-Party CookiesConfidential ComputingSelf-Hosted VPNBlogAboutBrand GuidelinesAffiliatesContact UsLegal & Compliance

Products

  • Pricing
  • Cloud VPS
  • VDS
  • RAM-Optimized VDS
  • Storage-Optimized VDS
  • Windows VPS
  • Bitcoin VPS
  • DDoS Protection
  • Private Networking (VPC)
  • Floating IPs
  • Microsoft Licenses
  • Additional Server Support

Explore

  • Documentation
  • Developers API Docs
  • FAQ
  • Datacenter
  • Network
  • Looking Glass
  • Confidential Computing
  • Cookie Policy
  • Self-Hosted VPN

Company

  • Blog
  • Contact Us
  • About Us
  • Brand Guidelines
  • Affiliates

Legal & Compliance

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement
  • Acceptable Use Policy
  • Microsoft Software Terms of Use
  • Refund Policy
  • Report Abuse

Products

  • Cloud VPS
  • VDS
  • RAM-Optimized VDS
  • Storage-Optimized VDS
  • Windows VPS
  • Bitcoin VPS
  • DDoS Protection
  • Private Networking (VPC)
  • Floating IPs
  • Microsoft Licenses
  • Additional Server Support
Pricing

Explore

  • Documentation
  • Developers API Docs
  • FAQ
  • Datacenter
  • Network
  • Looking Glass
  • Confidential Computing
  • Cookie Policy
  • Self-Hosted VPN

Company

  • Blog
  • Contact Us
  • About Us
  • Brand Guidelines
  • Affiliates

Legal & Compliance

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement
  • Acceptable Use Policy
  • Microsoft Software Terms of Use
  • Refund Policy
  • Report Abuse

© VPS.BG Ltd. 2026 · All rights reserved!

Made with passion in Bulgaria · VAT ID: BG203144520

Security & Privacy

Critical zero-day vulnerability found in 350,000+ WordPress installations

01 September 2020 • 3 min read

Contents

  • 700,000 Wordpress websites used the File Manager plugin. 52% of them were vulnerable
  • Types of exploits for the outdated WP File Manager plugin
  • Plugins that helped reduce the damage
  • The aftermath of the WP vulnerability

Subscribe to Our Newsletter

Join 5000+ subscribers and receive helpful content, deals and more! We promise no spam - 100% great content. Unsubscribe anytime.

Share Article

The popular and widely downloaded File Manager plugin for WordPress was identified to have a serious vulnerability back in 2020. 

This security breach essentially allowed unauthenticated users to run file manager commands by directly accessing an unprotected file from the plugin’s ‘elFinder’ package.

The file manager plugin in itself is a tool used by WordPress site administrators and owners to help with file management on their systems.

700,000 Wordpress websites used the File Manager plugin. 52% of them were vulnerable

This security breach wasn’t only on a couple of versions of the plugin. As a matter of fact, it affected all plugin versions from 6.0 to 6.8, making File Manager prone to backdoor access by hackers and to other cyberattacks.

The estimated number of affected WordPress installations was around 350 000, above half of the total number of hosted WordPress websites at the time of the exploit’s discovery.

The patched version - 6.9, was released on September 1st 2020, fixing all of the vulnerability issues and patching the installations, making them secure.

Types of exploits for the outdated WP File Manager plugin

However, WP websites that didn’t update to the 6.9 version of File Manager, continued to be a target for hackers. The most common tactics that was utilized by malicious hackers was to first publish a manuscript entitled hardfork.php using the exploit and then utilize that script to upload malicious code right into the default WordPress manuscripts, which could be found at the /wp-admin/admin-ajax.php and /wp-includes/user.php directories.

Some hackers even went as far as password-protecting the vulnerable file, preventing others from already exploiting the infected sites. What this suggested was that the initial hackers, who broke in through the security, were planning to come back and deal extra damage.

There were also those hackers who were just testing the limitations of the system and the exploit rather than wanting to do wrong. These individuals just injected empty files into the WP installation to understand how the vulnerability happened and whether access could be prevented.

All of this made it necessary for users to update to the patched 6.9 version as soon as possible in order to avoid their websites being exploited as well.

Plugins that helped reduce the damage

One WP plugin that was able to help mitigate the impact and even prevent any damage was Wordfence. They mentioned having blocked more than 450 000 total exploit attempts over the period of time when the exploit was initially discovered.

The aftermath of the WP vulnerability

This particular case made it clear that such utility plugins could be an unforeseen backdoor and should be installed and monitored with caution. It also showed the importance of keeping your system and its files up to date and how that can affect your privacy and security.

Subscribe to Our Newsletter

Join 5000+ subscribers and receive helpful content, deals and more! We promise no spam - 100% great content. Unsubscribe anytime.

Share Article

You Might Also Like

Cloud Hosting

8 steps to speed up your WordPress website

11 November 2020 • 10 min read

Over the last couple of decades search engines have been constantly releasing updates in order to improve their results and to present online users with the information they are looking for in a quick…

Security & Privacy

How to protect your server and website from DDoS attacks

30 August 2020 • 5 min read

Given the alarmingly high number of recent online cyberattack rates, it is unsurprising that DDoS attacks have also increased in regularity.Since we previously discussed the nature of DDoS attacks and…

Cloud Hosting

7 useful tips for choosing a reliable hosting provider

08 July 2021 • 7 min read

Need a hosting provider but don’t know what to look for? We’ve got you covered!We know that when looking at 2 or more similar products or services, the price is usually the deciding factor that determ…

Security & Privacy

What is a DDoS attack? Common types of DDoS attacks

28 June 2020 • 7 min read

The online world is constantly bombarded with cybercrime. Over the last couple of decades, there has been a dramatic increase in online cybercrime and cyberattack rates with a drastically high number…

Get a powerful and secure cloud server with WordPress today!

Configure