Skip to main content

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

0
High
Malwarewordpress
Published: 09/15/2026 (09/15/2026, 20:34:15 UTC)
Source: Bleeping Computer

Description

Malicious versions of the Admin Menu Editor Pro WordPress plugin were distributed after the maintainer's website was compromised. The attacker pushed a trojanized update (version 2.35) that installed a web shell and created a hidden user account on affected sites. Approximately 230 customers installed the malicious update on at least 1,500 sites. A subsequent clean update (2.36) was also compromised. The developer removed the malicious updates and took the website offline to prevent further damage. Users are advised to check for specific indicators of compromise and restore from backups or manually remove malicious files and database entries.

Affected software

Affected versions
=2.35=2.36

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 20:46:43 UTC

Technical Analysis

An attacker compromised the adminmenueditor.com website and pushed malicious updates to the Admin Menu Editor Pro WordPress plugin, specifically version 2.35, which included a web shell in includes/wp-user-consent.php and created hidden user accounts. This malicious update was available from approximately 06:00 to 13:00 UTC on the day of compromise and was installed by about 230 customers on 1,500 sites. The developer released a clean version 2.36 the same day, but the attacker also compromised this version. The attacker likely had root-level server access. The free version of the plugin and version 2.34 are believed to be clean. The developer recommends restoring from backups prior to September 14 or manually removing malicious files and database entries.

Potential Impact

The malicious plugin versions installed a web shell and created hidden user accounts, allowing unauthorized access and potential full control over affected WordPress sites. At least 1,500 sites were compromised, with the possibility of more due to the compromised clean update. This backdoor could enable attackers to maintain persistent access, manipulate site content, or use the sites for further attacks.

Defensive Guidance

The developer removed the malicious updates and took the website offline to prevent further compromise. Users who installed versions 2.35 or 2.36 should check for the presence of includes/wp-user-consent.php, a /wp-content/object-cache/ directory, hidden wp_ users in the wp_users table, and wp_ocache* options in the wp_options table. The most reliable remediation is restoring affected sites from backups made before September 14. If restoration is not possible, users should delete the malicious plugin versions, the object-cache directory, and the malicious database entries. Version 2.34 and the free plugin version are not affected.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.71,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6aa9aeae55bf5e2cf55ad20b

Added to database: 09/15/2026, 20:46:38 UTC

Last enriched: 09/15/2026, 20:46:43 UTC

Last updated: 09/16/2026, 03:05:49 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses