Admin Menu Editor Pro Supply Chain Attack Backdoors 1,500 WordPress Sites
The official distribution infrastructure of the WordPress plugin Admin Menu Editor Pro was compromised, allowing attackers to embed malicious code into versions 2.35 and parts of 2.36 of the plugin. The tampered updates deployed a web shell via a rogue PHP file and created hidden administrator accounts on affected sites, impacting an estimated 1,500 WordPress installations across roughly 230 customers. The breach persisted even after the developer pulled version 2.35 and issued version 2.36, as the distribution server itself remained compromised at the time. Affected sites show signs of ongoing persistence including hidden users, rogue MU plugins, database modifications, and PHP files that may survive plugin deletion. The developer has advised removing both affected versions, auditing the wp_users table directly, and restoring from backups predating September 14, 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in