• About Us
  • Contributors
  • Guides
  • Speaking Engagements
  • Write for The SEM Post
  • Submit a tip or contact us!
  • Newsletters

The SEM Post

Latest News About SEO, SEM, PPC & Search Engines

  • Google
  • SEO
  • Mobile
  • Local
  • Bing
  • Pay Per Click
  • Facebook
  • Twitter
  • State of the Industry
You are here: Home / SEO / Major Wordpress Exploit Affecting Hundreds of Thousands of Sites using RevSlider Premium Plugin

Major WordPress Exploit Affecting Hundreds of Thousands of Sites using RevSlider Premium Plugin

December 16, 2014 at 4:00 am PST By Jennifer Slegg

  • Facebook
  • Twitter
  • Google+
  • Pinterest
  • LinkedIn
  • Email
  • WhatsApp
  • Evernote
  • SMS

sliderrevolutionexploitAn exploit in a WordPress plug-in has resulted in the infection of over 100,000 WordPress websites since Sunday.  And what is worse, because the plugin is bundled with many themes, many webmasters might be unaware that they use it and are not getting plugin update reminders for what has been termed as a Zero Day exploit.

The exploited plugin is called Slider Revolution, a popular slideshow plugin utilized by many WordPress theme designers also known as RevSlide. It is a premium plug-in, which means users paid for the use of the plugin. But incredibly, even though the exploit was known and fixed earlier this year, RevShare never announced that there was a problem with the plugin being exploited, leaving many webmasters unaware of the urgency required to fix it.  They also have a second plugin, ShowBiz Pro, that is also affected by the same exploit.

ThemePunch, the plugin creator, commented that they were instructed not to make the exploit public so that hacking instructions would not be easily available. While spammers have been using the back door to hack sites months ago, this major attack began on Sunday.

The exploit works simply by accessing a specific URL, which makes the wp-config.php file available to the hackers, who then have full database credentials to the site.

For RevSlide, you need to have version 4.2.0 or newer to be safe, which was released in February 2014.  For ShowBiz Pro, you need 1.5.3 or later, which was released in January 2014.

What makes this exploit worse, and harder to discover, is that this plug-in is also quietly bundled with many theme packages, so even if you don’t remember specifically installing this plug-in, it may have been used by the designer of your theme, and as such does not auto-update to the latest version and you will be unaware that there could be a possible exploit.  And even worse, many of these theme designers are still selling their WordPress themes with an older version of RevSlide, meaning even if you purchase the theme today, you can still be exploited.

Envato Market has a great updated list detailing all the themes they are aware of that are affected by this exploit.  It also details which themes have updated the included RevSlide and those which have not.

Google has also blocked many of these sites in their search results, in an attempt to limit the damage. So if your site is infected, potential visitors are going to see an alert that states the website contains malware and that they should not visit the website. If your site is infected, and Google has discovered it, there should also be an alert in your Google webmaster tools that your site contains malware.

Security site Sucuri, which was also the first site to detail this latest exploit, also offers a free scanner you can use to automatically check websites for malware, which can be handy for sites that have been exploited that have not yet been discovered by Google.

It is recommended that you update the plugin immediately.  Some are recommending to replace the swfobject.js and template-loader.php files to remove the exploit. But if your site has already been exploited, you will also need to change your database credentials as well, as the hackers will still have that information for your site to re-hack.

This also serves as a reminder that is always very important to keep WordPress updated, and not just WordPress itself but also all the plug-ins and themes you use. As is seen in this case, sometimes there are so-called Zero Day exploits that are fixed, yet aren’t publicized, so you may not know when there’s a severe vulnerability that you need to update to fix.

  • Facebook
  • Twitter
  • Google+
  • Pinterest
  • LinkedIn
  • Email
  • WhatsApp
  • Evernote
  • SMS
The following two tabs change content below.
  • Bio
  • Latest Posts
My Twitter profileMy Facebook profileMy Google+ profileMy LinkedIn profile

Jennifer Slegg

Founder & Editor at The SEM Post
Jennifer Slegg is a longtime speaker and expert in search engine marketing, working in the industry for almost 20 years. When she isn't sitting at her desk writing and working, she can be found grabbing a latte at her local Starbucks or planning her next trip to Disneyland. She regularly speaks at Pubcon, SMX, State of Search, Brighton SEO and more, and has been presenting at conferences for over a decade.
My Twitter profileMy Facebook profileMy Google+ profileMy LinkedIn profile

Latest posts by Jennifer Slegg (see all)

  • 2022 Update for Google Quality Rater Guidelines – Big YMYL Updates - August 1, 2022
  • Google Quality Rater Guidelines: The Low Quality 2021 Update - October 19, 2021
  • Rethinking Affiliate Sites With Google’s Product Review Update - April 23, 2021
  • New Google Quality Rater Guidelines, Update Adds Emphasis on Needs Met - October 16, 2020
  • Google Updates Experiment Statistics for Quality Raters - October 6, 2020

Filed Under: SEO, Tools, Wordpress Tagged With: Wordpress

Sign up for our newsletter


Comments

  1. Michael Finegold says

    December 29, 2014 at 12:52 pm

    The makers of Revslider have already dealt with that issue, no longer relevant.

    • Jennifer Slegg says

      December 30, 2014 at 1:34 am

      Yes, they had fixed it but there were many websites hit at the time the article was written that didn’t even realize it. There were also two issues… they never announced there was an issue so that users could be sure they were updated (which they did explain why they didn’t notify people until very recently). And many users had this plugin bundled in with various themes, which meant it wouldn’t use the auto-update plugin function within WordPress and theme creators are still distributing themes with the exploited plugin bundled in. The huge number of sites affected (and are still affected) shows that while Revslider fixed the issue, there are many who still need to update it themselves too.

  2. Andor Rosenberg says

    December 29, 2014 at 8:24 pm

    Hi Jennifer,

    I think it is important to avoid insinuating that this is WordPress exploit. It is not. It is an third party plugin exploit. I strongly suggest you rephrase your title to avoid hundreds and thousands of WordPress designers and developers being questioned by their clients about the stability and security of WordPress.

    – Andor Rosenberg.

    • Jennifer Slegg says

      December 30, 2014 at 1:31 am

      The article is quite clear it isn’t an exploit within WordPress but with a plugin used in conjunction with WordPress. Unfortunately, many users are not even aware they are using this plugin because it was bundled in with themes released by various theme designers, which meant it would not auto-update for them.

Trackbacks

  1. WP Super Cache Latest Plugin With Major XSS Exploit, Requires Immediate Update - The SEM Post says:
    April 8, 2015 at 3:35 am

    […] a discovered exploit patched.  Google Analytics by Yoast, WordPress SEO by Yoast, Shareaholic, RevSlider and Fancybox-for-Wordpress have all recently fixed exploits, so you should also double check you […]

  2. Major WordPress Exploit Affecting Sites with Shareaholic Social Media Sharing Plugin - The SEM Post says:
    April 10, 2015 at 2:48 am

    […] WordPress plugins over the last few months, including SEO by Yoast, Fancybox-for-Wordpress and Revslider Premium Plugin. It is worth reminding those that use WordPress that they should regularly update all their […]

  3. Many Wordpress Plugins With XSS Exploit, Wordpress SEO, All in One SEO & Google Analytics by Yoast Affected - The SEM Post says:
    April 21, 2015 at 4:50 am

    […] WordPress plugin exploits, including Google Analytics by Yoast, SEO by Yoast, Shareaholic, RevSlider and […]

Founder & Editor

Jennifer Slegg (2052)

Sign up for our daily news recap & weekly newsletter.


Follow us online

  • Facebook
  • Google+
  • Linkedin
  • Pinterest
  • Twitter

Latest News

2022 Update for Google Quality Rater Guidelines – Big YMYL Updates

We finally have the first Google Quality Rater Guidelines update of 2022, and like usual, it is … [Read More...]

Recent Posts

  • 2022 Update for Google Quality Rater Guidelines – Big YMYL Updates
  • Google Quality Rater Guidelines: The Low Quality 2021 Update
  • Rethinking Affiliate Sites With Google’s Product Review Update
  • New Google Quality Rater Guidelines, Update Adds Emphasis on Needs Met
  • Google Updates Experiment Statistics for Quality Raters
  • Analyzing “How Google Search Works” Changes from Google
  • Google Quality Rater Guidelines Update: New Introduction, Rater Bias & Political Affiliations
  • Google Updates Quality Rater Guidelines: Reputation for News Sites; Video Content Updates; Quality for Information Sites
  • Google Makes Major Changes to NoFollow, Adds Sponsored & UGC Tags
  • Google Updates Quality Rater Guidelines Targeting E-A-T, Page Quality & Interstitials

Categories

  • Affiliate Marketing
  • Amazon
  • Apple
  • Bing
  • Branding
  • Browsers
  • Chrome
  • Content Marketing
  • Design
  • Domains
  • DuckDuckGo
  • Email
  • Facebook
  • Firefox
  • Foursquare
  • Google
    • Analytics
    • Google RankBrain
    • Quality Rater's Guidelines
  • History of Search
  • Industry Spotlight
  • Instagram
  • Internet Explorer
  • Links
  • Local
  • Mobile
  • Native Advertising
  • Other Search Engines
  • Pay Per Click
  • Pinterest
  • Publishers
  • Security
  • SEO
  • Snapchat
  • Social Media
  • State of the Industry
  • The SEM Post
  • Tools
  • Twitter
  • Uncategorized
  • User Experience
  • Video Marketing
  • Week in Review
  • Whitepapers
  • Wordpress
  • Yahoo
  • Yelp
  • YouTube
December 2025
MTWTFSS
« Aug  
1234567
891011121314
15161718192021
22232425262728
293031 

Meta

  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org

Copyright © 2025 · News Pro Theme On Genesis Framework · WordPress · Log in