LmCast :: Stay tuned in

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Recorded: Sept. 15, 2026, 9:01 p.m.

Original Summarized

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

News

Featured
Latest

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Homebrew 7.0.0 gets built-in GUI, better security controls

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

New Android malware encrypts files, steals data, and harasses victims

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Cover 10 devices with 5 years of AdGuard VPN for $34.97

CenterPoint Energy confirms customer data stolen in cyberattack

BambooToken malware controls Windows and Linux systems via MQTT

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityMalcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

By Bill Toulas

September 15, 2026
04:34 PM
0

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account.
Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites.
After noticing the intrusion, Elsts removed the malicious update and pushed a clean version 2.36 on the same day at 19:00 UTC. However, the hacker still had access to the website and compromised the new version, too.
Admin Menu Editor Pro is the premium version of Admin Menu Editor, a WordPress plugin present on more than 300,000 sites that allows administrators to customize their Dashboard menu, hide plugins from other users, set per-role access limits, and create login/logout redirects.
Elsts told BleepingComputer that the malicious Admin Menu Editor Pro version 2.35 was available on the official website from approximately 06:00 to 13:00 UTC. The malicious PHP code it contained also created a hidden user account.
According to the developer, at least 230 customers installed the malicious update on 1,500 sites. However, Elsts warns that the victim count could be larger since it is difficult to determine the number of customers running a trojanized version 2.36 of the plugin.
"Based on analysis of update server logs, approximately 230 customers were affected in the initial attack. The malicious version was installed at least 1500 sites (often multiple sites per customer)," Elsts told BleepingComputer.
"Several hundred additional customers downloaded the plugin in or near the relevant time window, and could have also been affected," the developer added.
The investigation indicates that the attacker likely had root-level server access, so Elsts decided to protect customers by taking the website offline until it could be restored with confidence.
Currently, Ests published a static page with details about the incident and what customers can do to check if they are affected, along with recommendations to restore compromised websites to a safe state. 
Anyone who installed versions Admin Menu Editor Pro 2.35 and 2.36 should check for the following signs of compromise:
includes/wp-user-consent.php in the admin-menu-editor-pro directory
A new /wp-content/object-cache/ directory
A user beginning with wp_ in the wp_users table, which may be hidden from the WordPress dashboard
Options named like wp_ocache* in the wp_options table
Version 2.34 is believed to be clean, and the free version of Admin Menu Editor does not appear to be affected.
Elsts says that the most reliable fix is to restore a compromised site from a safe backup before September 14. If this is not possible, the developer recommends deleting the plugin, the "/wp-content/object-cache/" directory, and the above database entries.
The developer of the Admin Menu Editor WordPress plugin said the incident was limited to its infrastructure and apologized to affected customers.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
BdThemes plugins supply-chain hack creates rogue WordPress adminsHackers target WordPress sites via third-party WooCommerce pluginCritical Elementor Pro flaw exploited to take over WordPress sitesWordPress backup plugin flaw exposes millions of sites to takeover attacksHackers push malicious Virtualizor update in BGP hijacking attack

Admin Menu Editor
Plugin
Supply Chain
Supply Chain Attack
WordPress

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft releases emergency Windows updates to fix RDS failures

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Microsoft: September updates cause RDS failures on Windows Server

Sponsor Posts

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

Overdue a password health-check? Audit your Active Directory for free

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Malicious versions of the Admin Menu Editor Pro plugin for WordPress were distributed to over 200 customers following a security breach involving the maintainer’s website, which allowed a threat actor to push malicious updates that created hidden user accounts. The incident centers on the Admin Menu Editor Pro, a premium WordPress plugin utilized on more than 300,000 sites to provide administrators with features such as customizing the dashboard menu, restricting plugin visibility, setting role-based access limits, and managing login/logout redirects.

The intrusion occurred when an unauthorized party accessed the adminmenueditor.com website and uploaded version 2.35 as an update for the plugin's Pro version, which contained the file includes/wp-user-consent.php. This file was instrumental in installing a web shell on the affected websites. The developer, Janis Elsts, responded by removing the malicious update and releasing a clean version 2.36 on the same day. However, the attacker maintained access and compromised the newly released version as well.

The malicious version 2.35 was publicly available on the official website approximately between 06:00 and 13:00 UTC. Analysis of update server logs indicated that at least 230 customers were initially affected, and the malicious update was installed across a minimum of 1,500 sites, often involving multiple sites per customer. The developer noted that because the attacker likely possessed root-level server access, customers were advised to take protective measures.

To assist affected parties, the developer published a static page detailing the incident, providing instructions on identifying compromise indicators, and recommending steps to restore compromised websites to a secure state. Individuals who installed versions 2.35 and 2.36 must inspect their systems for specific signs of compromise, including the presence of includes/wp-user-consent.php within the admin-menu-editor-pro directory, the existence of a new /wp-content/object-cache/ directory, user accounts beginning with wp_ within the wp_users table that may be concealed from the WordPress dashboard, and options named like wp_ocache* in the wp_options table. The developer asserted that version 2.34 is considered clean, and the free version of the related plugin appeared unaffected.

The most reliable remediation strategy recommended by the developer involves restoring a compromised site from a secure backup taken prior to September 14. If restoration is not feasible, the developer suggested deleting the plugin, the /wp-content/object-cache/ directory, and any associated database entries to mitigate the threat. This incident highlights the pervasive risks associated with software supply chains, where malicious code can be injected through seemingly legitimate update mechanisms, leading to widespread compromise of user infrastructure.