Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro WordPress plugin were distributed after the maintainer's website was compromised. The attacker pushed a trojanized update (version 2.35) that installed a web shell and created a hidden user account on affected sites. Approximately 230 customers installed the malicious update on at least 1,500 sites. A subsequent clean update (2.36) was also compromised. The developer removed the malicious updates and took the website offline to prevent further damage. Users are advised to check for specific indicators of compromise and restore from backups or manually remove malicious files and database entries.
AI Analysis
Technical Summary
An attacker compromised the adminmenueditor.com website and pushed malicious updates to the Admin Menu Editor Pro WordPress plugin, specifically version 2.35, which included a web shell in includes/wp-user-consent.php and created hidden user accounts. This malicious update was available from approximately 06:00 to 13:00 UTC on the day of compromise and was installed by about 230 customers on 1,500 sites. The developer released a clean version 2.36 the same day, but the attacker also compromised this version. The attacker likely had root-level server access. The free version of the plugin and version 2.34 are believed to be clean. The developer recommends restoring from backups prior to September 14 or manually removing malicious files and database entries.
Potential Impact
The malicious plugin versions installed a web shell and created hidden user accounts, allowing unauthorized access and potential full control over affected WordPress sites. At least 1,500 sites were compromised, with the possibility of more due to the compromised clean update. This backdoor could enable attackers to maintain persistent access, manipulate site content, or use the sites for further attacks.
Mitigation Recommendations
The developer removed the malicious updates and took the website offline to prevent further compromise. Users who installed versions 2.35 or 2.36 should check for the presence of includes/wp-user-consent.php, a /wp-content/object-cache/ directory, hidden wp_ users in the wp_users table, and wp_ocache* options in the wp_options table. The most reliable remediation is restoring affected sites from backups made before September 14. If restoration is not possible, users should delete the malicious plugin versions, the object-cache directory, and the malicious database entries. Version 2.34 and the free plugin version are not affected.
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Description
Malicious versions of the Admin Menu Editor Pro WordPress plugin were distributed after the maintainer's website was compromised. The attacker pushed a trojanized update (version 2.35) that installed a web shell and created a hidden user account on affected sites. Approximately 230 customers installed the malicious update on at least 1,500 sites. A subsequent clean update (2.36) was also compromised. The developer removed the malicious updates and took the website offline to prevent further damage. Users are advised to check for specific indicators of compromise and restore from backups or manually remove malicious files and database entries.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An attacker compromised the adminmenueditor.com website and pushed malicious updates to the Admin Menu Editor Pro WordPress plugin, specifically version 2.35, which included a web shell in includes/wp-user-consent.php and created hidden user accounts. This malicious update was available from approximately 06:00 to 13:00 UTC on the day of compromise and was installed by about 230 customers on 1,500 sites. The developer released a clean version 2.36 the same day, but the attacker also compromised this version. The attacker likely had root-level server access. The free version of the plugin and version 2.34 are believed to be clean. The developer recommends restoring from backups prior to September 14 or manually removing malicious files and database entries.
Potential Impact
The malicious plugin versions installed a web shell and created hidden user accounts, allowing unauthorized access and potential full control over affected WordPress sites. At least 1,500 sites were compromised, with the possibility of more due to the compromised clean update. This backdoor could enable attackers to maintain persistent access, manipulate site content, or use the sites for further attacks.
Defensive Guidance
The developer removed the malicious updates and took the website offline to prevent further compromise. Users who installed versions 2.35 or 2.36 should check for the presence of includes/wp-user-consent.php, a /wp-content/object-cache/ directory, hidden wp_ users in the wp_users table, and wp_ocache* options in the wp_options table. The most reliable remediation is restoring affected sites from backups made before September 14. If restoration is not possible, users should delete the malicious plugin versions, the object-cache directory, and the malicious database entries. Version 2.34 and the free plugin version are not affected.
Technical Details
- Classification
- {"confidence":0.71,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6aa9aeae55bf5e2cf55ad20b
Added to database: 09/15/2026, 20:46:38 UTC
Last enriched: 09/15/2026, 20:46:43 UTC
Last updated: 09/16/2026, 03:05:49 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.