WordPress Plugin on 1M+ Sites Left Database Backups Public
A plugin on over 1 million WordPress sites has been leaving business databases open to download. We’re also tracking a flaw in one of the world’s most popular contact forms, three booking and payment plugins that mark orders as paid when no money arrived, an anti-fraud plugin that let blocked customers walk straight back in, and a reviews plugin that lets a basic customer account plant malicious code.
I’ve spent 25 years building production software and managing hundreds of clients’ websites. Let’s look at exactly what happened, the immediate risk to your business revenue, and how we can fix it right now.
Let’s start with the biggest risk to your customer data today. File Manager runs on over 1 million WordPress sites, and it has a backup feature. Versions 7.2.2 through to 8.0.4 saved those database backups in the public part of your website, and nothing stopped anonymous visitors from downloading them.
It hits sites where someone made a backup through the plugin, that file is still on the server, and your server ignores a standard protection file. A database backup is your entire business in a single file. Every user’s email address, every password in scrambled form, your form entries, your customers and your orders.
If that file was downloaded, this isn’t a hacked website. It’s a data breach. Nothing on your site will look any different.
So go to Plugins and update File Manager to version 8.0.5 or later. But here’s the trap: the update does not delete old backups. Open the plugin’s backup screen and delete every old database backup you don’t need.
Then ask your host whether those files were ever downloaded. And if you’re not actively using a file manager inside WordPress, remove it completely.
Next up is WPForms, the contact form plugin running on over 5 million websites. A flaw disclosed yesterday affects versions 1.5.0.1 through to 2.0.2.0. Shortcodes are the little codes in square brackets that plugins use to add features to your pages.
WPForms was echoing form submissions back onto the page without stripping those brackets out. So any anonymous visitor filling in your form could make your site run a shortcode. The business risk is limited by the fact that the attacker can only trigger shortcodes that already exist on your site, so the damage depends on what else you’ve got installed.
A simple brochure site carries limited risk, but membership, booking or ecommerce plugins have far more powerful shortcodes. Those could expose information that was never meant to be public, including details of private file attachments. So update WPForms to version 2.0.2.1, and if you run ecommerce or membership plugins alongside it, do it today.
Next up, if your website takes bookings or payments, pay close attention to this one. Three plugins were disclosed yesterday with the same fatal mistake: they trusted what the visitor’s browser said about payment.
Bookly, on over 60,000 sites, let anyone set a booking total to zero. That means paid services booked for free. Paymattic didn’t check that a Stripe payment belonged to the right order, and Verge3D never confirmed with the payment provider that a payment happened at all.
So there’s no login required and no hacking alarms. Your website simply says paid when you weren’t. That’s services delivered for nothing, stock shipped without payment and staff time burned, and most businesses won’t notice until reconciliation.
So update Bookly to 28.3, Paymattic to 4.6.26 or later and Verge3D to 4.13.1. Then reconcile. Compare every paid booking and order on your website against what actually landed in Stripe or PayPal, and look for $0 bookings and orders marked paid with no matching transaction.
Next up, many WooCommerce store owners install Blacklist Manager to lock out fraudsters. Ironically, versions 1.3.0 through to 2.3.1 didn’t enforce the block on every login route. So a fraudster you thought you’d shut out could still sign in, keep ordering, use saved details and rack up chargebacks.
And if you blocked a former staff member instead of deleting them, they kept their old access. So update to version 2.3.2, review orders from blocked customers since the day you blocked them, and properly delete or downgrade any ex-staff accounts.
And finally, WP Review Slider Pro. Businesses use it to showcase customer reviews. Versions before 12.7.12 let anyone with a basic login hide malicious code inside the plugin.
If an administrator then interacts with that planted content, the code runs with their permissions, and that’s a path to full site takeover, launched from the very widget you use to build customer trust. It matters most if your site lets anyone register an account, as many online stores do.
So update to version 12.7.12 and check your stored reviews and slider settings for anything strange. And if you don’t need open registration, switch it off under Settings, then General.
Today’s top priority is your customer data. If you’ve ever made a backup with File Manager, find it and delete it today. But here’s the harsh reality: keeping your business safe is much bigger than clicking an update button.
Updating File Manager doesn’t delete a backup that’s already exposed. Updating Bookly doesn’t undo free bookings that already went through. Closing a vulnerability stops future attacks, but it does nothing to clean up what already happened.
So if you don’t have time to audit server files, monitor CVE databases or reconcile your orders each week, you shouldn’t have to carry that technical anxiety alone. Let my team handle your daily website security, cloud backups and structural SEO health through our active website care plans, and let’s protect your digital assets today.