Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Recorded: Sept. 15, 2026, 9:01 p.m.
| Original | Summarized |
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites News Featured Hackers hijack HBO Max Reddit account to push malware in ClickFix ads Homebrew 7.0.0 gets built-in GUI, better security controls Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent New Android malware encrypts files, steals data, and harasses victims Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites Cover 10 devices with 5 years of AdGuard VPN for $34.97 CenterPoint Energy confirms customer data stolen in cyberattack BambooToken malware controls Windows and Linux systems via MQTT Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityMalcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites By Bill Toulas September 15, 2026 Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Admin Menu Editor Bill Toulas Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Microsoft releases emergency Windows updates to fix RDS failures Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Microsoft: September updates cause RDS failures on Windows Server Sponsor Posts Patch automation needs more than speed. Action1 brings control into every stage of deployment. Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday. EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Watch a working exploit hit live controls and see exactly what blocks, detects, or misses Overdue a password health-check? Audit your Active Directory for free Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
Malicious versions of the Admin Menu Editor Pro plugin for WordPress were distributed to over 200 customers following a security breach involving the maintainer’s website, which allowed a threat actor to push malicious updates that created hidden user accounts. The incident centers on the Admin Menu Editor Pro, a premium WordPress plugin utilized on more than 300,000 sites to provide administrators with features such as customizing the dashboard menu, restricting plugin visibility, setting role-based access limits, and managing login/logout redirects. The intrusion occurred when an unauthorized party accessed the adminmenueditor.com website and uploaded version 2.35 as an update for the plugin's Pro version, which contained the file includes/wp-user-consent.php. This file was instrumental in installing a web shell on the affected websites. The developer, Janis Elsts, responded by removing the malicious update and releasing a clean version 2.36 on the same day. However, the attacker maintained access and compromised the newly released version as well. The malicious version 2.35 was publicly available on the official website approximately between 06:00 and 13:00 UTC. Analysis of update server logs indicated that at least 230 customers were initially affected, and the malicious update was installed across a minimum of 1,500 sites, often involving multiple sites per customer. The developer noted that because the attacker likely possessed root-level server access, customers were advised to take protective measures. To assist affected parties, the developer published a static page detailing the incident, providing instructions on identifying compromise indicators, and recommending steps to restore compromised websites to a secure state. Individuals who installed versions 2.35 and 2.36 must inspect their systems for specific signs of compromise, including the presence of includes/wp-user-consent.php within the admin-menu-editor-pro directory, the existence of a new /wp-content/object-cache/ directory, user accounts beginning with wp_ within the wp_users table that may be concealed from the WordPress dashboard, and options named like wp_ocache* in the wp_options table. The developer asserted that version 2.34 is considered clean, and the free version of the related plugin appeared unaffected. The most reliable remediation strategy recommended by the developer involves restoring a compromised site from a secure backup taken prior to September 14. If restoration is not feasible, the developer suggested deleting the plugin, the /wp-content/object-cache/ directory, and any associated database entries to mitigate the threat. This incident highlights the pervasive risks associated with software supply chains, where malicious code can be injected through seemingly legitimate update mechanisms, leading to widespread compromise of user infrastructure. |