A major security breach has compromised nearly 1,500 WordPress sites through a backdoored version of the Admin Menu Editor Pro plugin. The malicious update was pushed to customers via the official website after a threat actor gained unauthorized access to the maintainer’s site on Monday.
The compromised plugin, Admin Menu Editor Pro, is a premium version of the popular Admin Menu Editor plugin, which allows administrators to customize their Dashboard menu and control user access. According to developer Janis Elsts, over 200 customers installed the malicious update, resulting in approximately 1,500 affected sites.
The malicious code was inserted into an update for version 2.35 of the Pro plugin, which included a web shell that allowed the attacker to gain root-level server access. This enabled them to install a hidden user account on affected websites, making it difficult for administrators to detect the compromise. The malicious update was available on the official website from approximately 06:00 to 13:00 UTC before Elsts removed it and pushed a clean version 2.36.
However, due to the attacker’s persistence, even this clean update contained the same malicious code, highlighting the severity of the breach. Elsts warned that the actual number of affected sites could be higher, as several hundred additional customers downloaded the plugin in or near the relevant time window and may also have been compromised.
To mitigate the damage, Elsts published a static page with instructions on how to check for signs of compromise and restore affected websites to a safe state. Administrators who installed versions 2.35 and 2.36 should look for specific indicators, including the presence of an includes/wp-user-consent.php file in the admin-menu-editor-pro directory and a new /wp-content/object-cache/ directory.
In the worst-case scenario, administrators may need to restore their site from a safe backup before September 14 or delete the plugin, the “/wp-content/object-cache/” directory, and affected database entries. Elsts emphasized that version 2.34 is believed to be clean, and the free version of Admin Menu Editor does not appear to be affected.
The incident highlights the importance of staying vigilant when it comes to plugin updates and the need for robust security measures in place to detect and prevent such breaches. Administrators are advised to regularly back up their sites, monitor update logs closely, and maintain a secure environment to minimize the risk of similar incidents occurring in the future.
Source: Bleeping Computer — 2026-09-15