WordPress · Security · Small Business
WordPress Just Screwed 5 Million People. Are You One of Them?
A backup plugin had a hole in it. 5 million sites run that plugin. Nobody told any of them.

I got an email this morning. A plugin I know had a hole in it. 5 million sites run that thing. Not some junk plugin. The backup one. The one you install so you don't lose it all.
I've put it on other people's sites myself. So I sat down and looked at the dates. Found August 14. Fixed August 20. Six days, and that's fast work.
No complaints there. That's not the part that got me.
Nobody told the people running it. No email. No alert. Nothing on their screen. 5 million sites stood wide open for weeks and not one owner knew a thing.
And if you don't pay extra, you stood open thirty days longer than the guy who does. You might be one of them. Takes two minutes to find out.
I'm not saying your site got hacked. I'm saying it stood open and nobody sent you a note.
TL;DR
A backup plugin had a hole in it. Every version up to 7.109. 5 million sites run it. If you ran one, you were open, and nobody told you. The makers fixed it in six days, which is fast. But the people who pay Wordfence got covered on August 16. The rest waited until September 15. Go open your plugin list.
3 Things to Remember
You Were Wide Open. Nobody Told You.

Let me be straight about my own headline. I'm not saying 5 million sites got broken into. Nobody knows that number and I won't make one up. What I'm saying is worse than that.
The hole sat in every version up to 7.109. Not a rare setup. Not an edge case. If you had that plugin, you had the hole. Setting the trap took nothing from you. No login. No password. No click.
You didn't slip up, because there was no slip up to make. And nobody told you. Not when they found it. Not while it sat there open. So there was no move a careful owner could have made. Not one.
That's the case and it holds for all 5 million. You got screwed the day that code shipped. You just didn't know it yet. That's the part I'd be sore about.
Wordfence wrote up the tech side. It's all here. Rated 8.8 out of 10.
It Waits for You to Pull the Trigger.

This one is nasty. The bad instruction gets planted early and then it just sits there. It doesn't do a thing yet. It goes off later, when somebody restores a backup.
Which is the whole job of a backup plugin. So the tool you got to save you is the one that fires it. And you push the button. On a normal Tuesday. Doing the right thing.
One limit, and I'll say it plain. It doesn't go off on its own. It takes an owner sending the site out and loading it back in. Wordfence says that. So do I.
That doesn't make you safe. It makes you blind to it, which is worse. You can't stand guard against your own backup button. That's the whole trick of the thing. I'm not printing how any of it works. Go read the writeup if you want that part.
Six Weeks Ago I Said It Was the Core. It's the Plugins Again.

For years I had one line and I used it on everybody. It's not WordPress. It's the plugins. Then a hole turned up in WordPress itself. I had to eat that one in print.
I wrote it up and put my name on it. The feds put that hole on a list of ones being used right now. So I won't sit here and act like I've had this figured out the whole time.
But look what happened next. That one was the exception. This is the rule. And it came right back around inside of six weeks. One bad month is a story. This is not one bad month. Pick any month you want and count the WordPress holes in it.
It's never zero. It's never anywhere close to zero, and it hasn't been for years. Most of them come in through a plugin, same as this one. I did that math already.
So I'm not writing this up as news. It's a Tuesday on WordPress. There will be another one along shortly. Probably before you finish reading this page.
Nobody Did Anything Wrong. You Still Weren't Told.

Everybody in this story did their job, and I'll give them that up front. A guy named Jack Taylor found it on August 14. He got paid $5,761 for it. Wordfence checked his work and told the makers the next day. The makers said yes that's real on August 17.
The fix shipped August 20. Six days. That's fast and I won't pretend it isn't. Now count who's in that story. The guy who found it. The security outfit. The people who write the plugin.
You're not in it. You didn't write the code, you don't get the email, and you can't fix a thing you can't see. So being careful didn't help you here. It never even touched the thing.
Everybody in that chain did good work and you still stood open the whole time. That's the part that gets me. It's not a plugin problem. It's the deal WordPress hands you.
Mistake: you think being careful is what keeps your site safe.
Fix: count how much of your site is code you can't see.
Payoff: you find out how much of this you actually control. It's less than you think.
Some People Were Covered on Day Two. You Weren't.

Wordfence sells security and they give a version of it away too. The people who pay got a block on August 16. That's two days after the thing was found. Two days is nothing. That's a good outfit moving quick.
The rest got the same block on September 15. Same hole. Same site. Same risk. Thirty days apart, and the only thing between those two piles is what they pay.
I'll be fair here because it matters. Wordfence pays for the work that turns this stuff up. They paid that guy $5,761. And they do hand it to everybody in the end. That's a real business doing real work. It's not a shakedown and I won't call it one.
Fine. Now look at where all that leaves you on an ordinary Tuesday. On WordPress, your safety is a thing somebody else sells. And the one you didn't buy shows up a month late.
Add that to hosting. The theme. The plugins. The guy who bills you every month. Then tell me WordPress is cheap. I added it all up here.
You were in a race on August 16. Nobody told you that you'd entered it.
Are You One of Them? Go Look.
I put that in the headline, so here's the answer. Two minutes and nothing to sign up for.
1. Log into WordPress. Click Plugins. That's the list of everybody holding a key to your site.
2. Look for All in One WP Migration and Backup. Not there? Then this one isn't yours. Go run your business.
3. Read the version number next to it. 7.110 or higher, you're clear. 7.109 or lower, update it now.
That's the fix. That's the whole fix, and it takes about a minute of your day. One more thing, though, and I mean this one. An old version doesn't mean somebody came in the door. It means the door was unlocked. Those are two different things and I won't blur them to scare you into anything.
Here's when to stop and call somebody. If you're on an old version and you restored a backup lately, don't sort it out yourself. Get a person who does this for a living. That's not a job for a Sunday afternoon.
I Moved 1,387 of My Own Posts Off This.
I didn't write this from the cheap seats. I ran my own business on WordPress for years. I got tired of reading about holes in my own site. So I moved 1,387 of my own posts off it.
Mine. Not a client's. There's no backup plugin on this page and no plugin at all. So this morning's email isn't about me. Not because I'm any sharper than you are. Because there's nothing here for it to be about. That's the only trick I've got.
Here's how that move went, rankings and all. It wasn't as bad as I'd built it up to be.
Where This Plugin Was Actually Fine.

Fair is fair, so here's the other side of it. That plugin did its job for years. For millions of people, quietly, without any trouble at all. It's good software.
This was one bad bug and the makers fixed it in six days. I've waited longer on parts. If you're on 7.110 you're fine. Close the tab and go run your business.
And if somebody real watches your site, this whole thing stays small. Somebody who reads the warnings. Somebody who updates things inside a couple of days. That person is worth every dollar you pay them.
I mean all of that. There's no trap waiting in the next line.
Here's who that isn't. Most shops don't have that person and never did. They've got a plugin list nobody has opened in two years, and a guy who answers sometimes. Next month it'll be a different plugin with a different number. That part never changes.
Nothing to Patch.
I'm not telling you your site is on fire. It probably isn't, and I'd say so if it were. I'm telling you it stood open for weeks, you had no way to know, and you only found out because you read this.
That's the part I'd fix. Not the plugin. The setup that let it happen without you. What you want isn't a new website. It's not thinking about this on a Sunday.
If you want to see your site with no plugin list at all, take a test drive. I'll put your site on my code. Look at it before you spend a dime.
And if you'd rather read how I think about all of it first, that's what Balls Out Marketing is for.
Want the whole playbook first? Plan your attack. Balls Out Marketing.
FAQ
Yes, on 7.110 and later. The makers shipped the fix on August 20, 2026. That was six days after it got reported, which is fast work. If you're on 7.110 or higher you're clear on this one and there's nothing to do.
Three steps, about two minutes. Log into WordPress and click Plugins. Look for All in One WP Migration and Backup. Not in the list? Then this one isn't yours. If it's there, read the version number next to it. 7.110 or higher and you're clear. 7.109 or lower, update it now.
No. An old version means the door was unlocked. It doesn't tell you anybody walked through it. Those are two different things. If you're on an old version and you also restored a backup or moved the site lately, don't sort that out yourself. Get somebody who does this for a living.
Not really, and I'll say it plain. They got told on August 15, confirmed it on August 17, and shipped the fix on August 20. Six days is fast. The problem isn't that they were slow. It's that a hole in somebody else's code reached 5 million sites and nobody told the owners.
You don't have to. Here's what it buys. The people who pay Wordfence got a block on August 16. The rest got it September 15. Same hole, thirty days apart, and the only difference is what they pay. Wordfence funds the work that finds this stuff, so that part is fair.
A site built with no plugin layer. The features are part of the build instead of bolted on. So there's no plugin list, no warning that applies to you, and no version number to go read on a Sunday. You can see one on your own market before you spend a dime.
Read These In This Order
- WordPress Sucks Ass. Don't Let it Destroy Your Business.
- WordPress Left Your Site Wide Open. The Feds Noticed.
- Hundreds of Holes With No Fix Coming
- Stop Being Held Hostage by Your Plugins
- The WordPress Bill Nobody Adds Up
- Leave WordPress
Check Out My Last 3 Builds
Real sites, built with this exact system. Tap any one and poke around.