Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Over 1,500 WordPress websites have been compromised by a malicious Admin Menu Editor Pro plugin update that backdoored thousands of sites. The incident is a stark reminder of the importance of cybersecurity measures for website owners and developers.

The compromise occurred when an unauthorized party gained access to the adminmenueditor.com website and pushed out a malicious update, version 2.35, for the premium Admin Menu Editor Pro plugin. This update included a hidden user account creation tool, which allowed hackers to gain control over affected sites. What’s more alarming is that the hacker still had access to the website even after the developer removed the malicious update and pushed out a clean version 2.36.

Admin Menu Editor Pro is the premium version of Admin Menu Editor, a popular WordPress plugin used by over 300,000 websites. The plugin allows administrators to customize their Dashboard menu, hide plugins from other users, set per-role access limits, and create login/logout redirects. With its widespread use, it’s no wonder that thousands of sites were affected by the malicious update.

According to the developer, at least 230 customers installed the malicious update on over 1,500 sites. However, with hundreds more downloading the plugin during the same time frame, the actual number of compromised sites could be significantly higher. The hacker likely had root-level server access, which is why the developer was forced to take the website offline until it could be restored with confidence.

So, what can website owners do to protect themselves? First and foremost, they should check for any signs of compromise on their site. This includes looking for a hidden user account in the wp_users table, an object-cache directory, or database entries named like wp_ocache*. If you installed versions 2.35 or 2.36, it’s essential to take action immediately.

The most reliable fix is to restore your site from a safe backup taken before September 14. If this isn’t possible, the developer recommends deleting the plugin, the object-cache directory, and the affected database entries. By taking these precautions, you can minimize the risk of further attacks on your WordPress website.

This incident highlights the importance of website security and the need for developers to take cybersecurity measures seriously. Website owners should also be vigilant in monitoring their sites for any suspicious activity and stay informed about the latest security threats.


Source: Bleeping Computer — 2026-09-15