Skip to content

FBI Warning – WordPress Vulnerable to Hacker Attacks

2
272
FBI Warning – WordPress Vulnerable to Hacker Attacks

Editor's note, September 2026: this article reports an FBI public service announcement issued in April 2015. Every specific vulnerability named below was patched more than a decade ago, and the plugins involved have long since been fixed, renamed or removed from the WordPress plugin directory. We have kept the page because the underlying failure — premium plugins bundled inside themes that never get updated — is still one of the most common ways WordPress sites get compromised today. The original 2015 "solutions" have been removed, because two of them were plugins that no longer exist and one of those was itself an unofficial third-party patch. Current guidance is in the second half of this article.

What the FBI announced in 2015

In April 2015 the FBI's Internet Crime Complaint Center issued a public service announcement warning that WordPress sites were being defaced at scale, and urging site owners to patch their plugins. It followed a run of defacements against private and government websites across the United States and Europe. The announcement attributed the campaign to sympathisers of ISIL, on the basis of the imagery left on the defaced pages. The FBI's statement read: "Continuous Website defacements are being perpetrated by individuals sympathetic to the Islamic State in the Levant (ISIL) a.k.a. Islamic State of Iraq and al-Shams (ISIS)." FBI public service announcement on ISIL defacements exploiting WordPress vulnerabilities Crucially, the campaign was not targeting any particular kind of site. The attackers were scanning indiscriminately for known plugin vulnerabilities, which the FBI described as "easily exploited by commonly available hacking tools." Sites were hit because of what they had installed, not because of who they were. That is the detail worth carrying forward. Mass defacement campaigns then and now work the same way: a vulnerability is disclosed, an exploit is automated within days, and scanners sweep the entire internet looking for sites that have not applied the fix yet.

The 2015 vulnerabilities, and where they stand now

These were the plugins most commonly implicated at the time, according to security vendor Sucuri. All of these issues are long since fixed. This section is a historical record — treat it as context, not as a to-do list.

1. Slider Revolution (RevSlider)

Slider Revolution Responsive WordPress Plugin By far the largest contributor, with well over a hundred thousand reported compromises. A local file inclusion flaw disclosed in late 2014 allowed attackers to read arbitrary files — including wp-config.php, and with it the database credentials. It drove the SoakSoak mass-compromise campaign, and WP Tavern's coverage at the time advised immediate updates. The vendor patched it promptly. The reason it kept claiming victims for years afterwards is the part that still matters, and it is covered in the next section. The 2015 advice on this page recommended a third-party "Patch for Revolution Slider" plugin. That plugin was permanently closed on the WordPress plugin directory on 16 March 2020 and can no longer be installed. We no longer recommend it, and you should not go looking for a replacement: installing unofficial patch plugins means running unreviewed code that hooks your site in order to work around a bug the vendor has already fixed. Update the real plugin instead.

2. FancyBox for WordPress

FancyBox for WordPress A zero-day disclosed in February 2015 allowed unauthenticated attackers to inject a malicious script into site settings. This one has a happy ending: FancyBox for WordPress is still on the plugin directory, still actively maintained, and tested against current WordPress releases. The 2015 flaw was fixed at the time. If you are running it, just keep it updated like anything else.

3. MailPoet

MailPoet Newsletters A remote file upload vulnerability in the plugin then published as wysija-newsletters let attackers upload a PHP file without authenticating. It was exploited widely within days of disclosure. The plugin was subsequently rewritten and is published today as MailPoet, which is actively maintained and tested against current WordPress. The vulnerable 2014 codebase is not what you would be installing now.

4. Gravity Forms

An arbitrary file upload flaw, documented by Sucuri, affected older releases. Gravity Forms is a commercial plugin distributed by its vendor rather than through the WordPress plugin directory, so it updates only while you hold a current licence — see the section below on why that matters. The flaw was patched in 2015. A separate database takeover vulnerability was disclosed around the same time in the unrelated Custom Contact Forms plugin.

5. WP Symposium Pro

WP Symposium social networking plugin WP Symposium was a social-networking plugin that turned a WordPress site into a community platform. An unauthenticated file upload vulnerability in 2014 made it a favourite target. WP Symposium Pro was permanently closed on the WordPress plugin directory on 11 September 2022. It receives no updates and cannot be installed. If you still have it on a site, deactivate and delete it — an abandoned social-networking plugin is a large amount of unmaintained code handling user-submitted content and file uploads. If you need community or social features on WordPress today, BuddyPress is the maintained option, and it is tested against current WordPress releases.

The lesson that is still true: bundled premium plugins do not update themselves

Slider Revolution was patched by its vendor within days. Sites kept getting compromised through it for years. Understanding why is the single most useful thing to take from this episode, because the same trap is wide open today. Slider Revolution is a commercial plugin sold on a marketplace. Thousands of premium WordPress themes bundled a copy of it as a selling point — "includes Slider Revolution, a $30 value". When you bought one of those themes, you got the plugin, but you did not get a licence for it. Which meant:
  • It did not appear in WordPress's update checks, because it is not distributed through the WordPress plugin directory.
  • It had no update key of its own, so it could not pull updates from the vendor either.
  • It could only be updated when the theme author shipped a new version of the theme containing a newer bundled copy — and many of them never did.
So a patch existed, and hundreds of thousands of installations had no route to receive it. Site owners had no idea, because nothing in their dashboard indicated an update was available. This has not been fixed by anything structural in the intervening decade. Premium plugins bundled in themes, page-builder add-ons, and plugins installed from a downloaded zip are all still invisible to WordPress's update system unless the vendor ships its own updater and you have an active licence.

What to do about it on your own sites

Find out what is actually installed and how it updates

Go to Plugins → Installed Plugins and look for entries with no "View details" link to the WordPress plugin directory. Those are your commercially distributed or hand-uploaded plugins, and they are the ones that will not auto-update. For each, work out: do I hold a current licence, and is the vendor's own updater active? If the answer to either is no, that plugin is frozen at whatever version you installed. Pay particular attention to sliders, form builders, page builders and anything bundled by a theme.

Turn on automatic updates

WordPress has had per-plugin and per-theme auto-updates built in since version 5.5. On the Plugins screen there is an "Automatic updates" column — enable it for everything you cannot personally commit to patching within a day or two of a release. Core minor releases update automatically by default; leave that alone. For anything distributed outside the plugin directory, auto-updates are only as good as your licence. Renew them, or remove the plugin.

Use Site Health

Tools → Site Health is part of WordPress core and needs no plugin. It will tell you about out-of-date core, plugins and themes, inactive plugins you have forgotten about, and an unsupported PHP version. Inactive plugins are worth calling out: deactivated code still sits on disk and can still be reachable by a direct request, so delete what you are not using rather than leaving it dormant.

Delete rather than deactivate

Every plugin and theme you are not using is attack surface with no upside. The compromises that follow a disclosure overwhelmingly hit sites running software nobody was paying attention to any more.

Subscribe to a vulnerability feed

The gap between a disclosure and automated exploitation is now measured in hours. Wordfence Intelligence and Patchstack both publish free WordPress vulnerability feeds you can follow by email or RSS, so you find out about a problem in something you run before a scanner does.

Run a firewall and malware scanner

Wordfence Security and Sucuri Security are both actively maintained and tested against current WordPress. Either will flag file changes and known-bad requests, and both ship rules for newly disclosed plugin vulnerabilities, which buys you some cover in the window before you patch. Install one, not both. None of this replaces updating. A firewall that blocks an exploit attempt is a safety net under a site that is still vulnerable.

Keep core current

The original version of this article closed by pointing at WordPress 4.1.2, which was the security release of the day in April 2015. The advice generalises: run the current release, let minor security releases install themselves, and read the release notes when a major version ships. Site Health will tell you if you have fallen behind.

Choosing a host that helps

The 2015 defacement wave pushed hosting providers to take WordPress-specific security more seriously, and the better ones now do a lot of this work for you — server-level patching, a managed firewall, malware scanning, automated off-site backups, and staging environments so you can test an update before it reaches visitors. If you are weighing up where to host a site you care about, our WordPress hosting comparison covers what each provider actually includes.

In short

The 2015 FBI warning was about specific plugins that were patched a decade ago. The reason it is still worth reading is that the mechanism it exposed has not gone away: a fix existing is not the same as a fix reaching your site. Check which of your plugins have no update path, close that gap, and turn on automatic updates for the rest.
Noor Mustafa RazaN
WRITTEN BY

Noor Mustafa Raza

I am a WordPress Developer and Designer, author @WPArena. I am providing Free WordPress consultation and can help you to install WordPress in a secure way to small businesses and bloggers.

Responses (2 )

  • ‌
    ‌
    ‌
    ‌
    ‌
    ‌
  • ‌
    ‌
    ‌
    ‌
    ‌
    ‌
  • ‌
    ‌
    ‌
    ‌
    ‌
    ‌