Yes. In September 2020, attackers exploited a critical zero-day in the WordPress File Manager plugin, wp-file-manager. Versions 6.0 through 6.8 were vulnerable to unauthenticated file uploads and remote code execution. Version 6.9, released on September 1, 2020, removed the vulnerable component, but updating a site that ran an affected version does not prove it was never compromised.
What happened in the File Manager plugin attack?
Wordfence reported active exploitation on September 1, 2020. The vulnerability was assigned CVE-2020-25213 and rated CVSS 10.0 (critical) by Wordfence. Tenable and Wordfence described the flaw as arbitrary file upload leading to remote code execution.
The problem was an unsafe elFinder connector, connector.minimal.php, exposed inside the plugin without effective access controls. Attackers could send requests to that file and use elFinder commands to create or upload PHP files. Wordfence described a technique that used mkfile to create an empty PHP file and put to write malicious code into it. Attackers then placed webshells in wp-content/plugins/wp-file-manager/lib/files/, giving them a way to run code on the site.
Which versions were affected, and what did version 6.9 fix?
Wordfence identified File Manager versions 6.0 through 6.8 as affected. The plugin released version 6.9 on September 1, 2020. That patch removed the vulnerable lib/php/connector.minimal.php file and related unsafe library material. Wordfence urged users to update immediately; Singapore’s Cyber Security Agency issued the same advice on September 3.
#1 Best Overall
Version 6.9 was the fix for this specific vulnerability at that time. The available historical reports do not establish the plugin’s current release or whether the 2020 campaign remains active in 2026. They also do not establish that 6.9 is an appropriate current version to install. Check the plugin’s present release information before making a current-version decision; do not treat the old patch number as a guarantee of present-day security.
How large was the 2020 campaign?
Wordfence reported more than 450,000 exploit attempts blocked in the first several days. The figures below are historical estimates and reports from Wordfence, not current threat measurements:
| Date | Wordfence report |
|---|---|
| September 1, 2020 | The plugin had more than 700,000 active installations; Wordfence rated the flaw CVSS 10.0. |
| September 4, 2020 | Wordfence estimated 37.4% of installations—about 261,800 sites—were still vulnerable, and reported attacks on more than 1.7 million sites. |
| September 10, 2020 | Wordfence reported attacks on more than 2.6 million sites. |
The September 4 and September 10 counts refer to sites reported as attacked; they are not counts of unique exploit requests or confirmed successful compromises.
How can you check whether a site was compromised?
If the site ran a vulnerable version while the exploit was circulating, treat the version history as a reason to investigate—not proof of compromise. Wordfence advised scanning sites that may have been affected. Check the following sources of evidence:
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →- Plugin files: Inspect
wp-content/plugins/wp-file-manager/lib/files/and the wider plugin directory for PHP files or other unexpected changes. Wordfence reported files namedhardfork.php,hardfind.php, andx.php. - A later-reported indicator: Wordfence identified
feoidasf4e0_index.phpas a prevalent indicator and gave its MD5 hash as6ea6623e8479a65e711124e77aa47e4c. A matching filename or hash is a warning sign, not a complete inventory of possible malware. - Web-server and WordPress logs: Look for unexpected requests to
connector.minimal.php, suspicious file-creation or upload activity, and activity around the time the site had an affected plugin version. - Malware scan: Run a reputable scanner. A clean scan alone cannot prove that an attacker never accessed the site, so consider it alongside file and log review.
Wordfence’s September 1 report listed historical attacking IP addresses including 185.222.57.183, 185.81.157.132, 185.81.157.112, 185.222.57.93, 185.81.157.177, and 185.133.157.133. Use these only as historical indicators to corroborate local log evidence; an IP match by itself does not confirm a compromise.
What should you do if the site had File Manager 6.0–6.8?
- Contain suspected activity. If you find suspicious files or requests, restrict access to the site or put protective controls in place while investigating, where your hosting setup permits.
- Remove the vulnerable component. If File Manager is not actively needed, uninstall it. Wordfence recommended removal when it was unnecessary because file-management access can increase the damage an attacker can do after compromising an administrator account.
- Investigate before assuming an update is enough. Review the site’s logs and files, and run a malware scan. If you find evidence of unauthorized access, rotate relevant credentials and investigate the extent of the compromise.
- Restore with confidence, not just convenience. If recovery is needed, use a known-clean backup where available. If you cannot establish that a backup is clean or determine the scope of unauthorized changes, seek a full malware investigation or qualified WordPress security support.
- Reduce the chance of a repeat incident. Keep WordPress and its plugins maintained, retain usable backups, and monitor the site. If you cannot reliably handle updates, log review, and scanning, managed hosting or security support may be a better fit.
The historical advisory establishes exploitation in August–September 2020; it does not establish that the same campaign is active now. A present-day assessment should be based on the site’s version history and current evidence, not on the old campaign totals alone.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

