Back to Feed
Supply ChainSep 15, 2026

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious Admin Menu Editor Pro plugin updates backdoor 1,500 WordPress sites.

Summary

A threat actor compromised the Admin Menu Editor Pro plugin's website, pushing malicious updates that created hidden user accounts and installed web shells on over 1,500 WordPress sites. The developer attempted to remove the malicious code, but the attacker re-compromised the site and the updated plugin. The website has been taken offline for restoration, and users are advised to restore from backups or manually remove malicious files and database entries.

Full text

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites By Bill Toulas September 15, 2026 04:34 PM 0 Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites. After noticing the intrusion, Elsts removed the malicious update and pushed a clean version 2.36 on the same day at 19:00 UTC. However, the hacker still had access to the website and compromised the new version, too. Admin Menu Editor Pro is the premium version of Admin Menu Editor, a WordPress plugin present on more than 300,000 sites that allows administrators to customize their Dashboard menu, hide plugins from other users, set per-role access limits, and create login/logout redirects. Elsts told BleepingComputer that the malicious Admin Menu Editor Pro version 2.35 was available on the official website from approximately 06:00 to 13:00 UTC. The malicious PHP code it contained also created a hidden user account. According to the developer, at least 230 customers installed the malicious update on 1,500 sites. However, Elsts warns that the victim count could be larger since it is difficult to determine the number of customers running a trojanized version 2.36 of the plugin. "Based on analysis of update server logs, approximately 230 customers were affected in the initial attack. The malicious version was installed at least 1500 sites (often multiple sites per customer)," Elsts told BleepingComputer. "Several hundred additional customers downloaded the plugin in or near the relevant time window, and could have also been affected," the developer added. The investigation indicates that the attacker likely had root-level server access, so Elsts decided to protect customers by taking the website offline until it could be restored with confidence. Currently, Ests published a static page with details about the incident and what customers can do to check if they are affected, along with recommendations to restore compromised websites to a safe state. Anyone who installed versions Admin Menu Editor Pro 2.35 and 2.36 should check for the following signs of compromise: includes/wp-user-consent.php in the admin-menu-editor-pro directory A new /wp-content/object-cache/ directory A user beginning with wp_ in the wp_users table, which may be hidden from the WordPress dashboard Options named like wp_ocache* in the wp_options table Version 2.34 is believed to be clean, and the free version of Admin Menu Editor does not appear to be affected. Elsts says that the most reliable fix is to restore a compromised site from a safe backup before September 14. If this is not possible, the developer recommends deleting the plugin, the "/wp-content/object-cache/" directory, and the above database entries. The developer of the Admin Menu Editor WordPress plugin said the incident was limited to its infrastructure and apologized to affected customers. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: BdThemes plugins supply-chain hack creates rogue WordPress adminsHackers target WordPress sites via third-party WooCommerce pluginCritical Elementor Pro flaw exploited to take over WordPress sitesWordPress backup plugin flaw exposes millions of sites to takeover attacksHackers push malicious Virtualizor update in BGP hijacking attack

Indicators of Compromise

  • malware — wp-user-consent.php

Entities

Admin Menu Editor Pro (product)WordPress (technology)