Cybersecurity

Admin Menu Editor Pro Distributor Site Breach Plants Backdoors in 1,500 WordPress Sites

An attacker distributed malicious copies of the Admin Menu Editor Pro plugin after compromising its developer’s website, leading to the installation of hidden user accounts and a web shell in at least 1,500 sites. More than 230 customers are believed to have been affected, with the number potentially higher because another version was also compromised.

2026-09-15
3 min read
4 views
فريق تحرير certi.news
Admin Menu Editor Pro Distributor Site Breach Plants Backdoors in 1,500 WordPress Sites

An attacker used unauthorized access to adminmenueditor.com to distribute two malicious versions of the Admin Menu Editor Pro WordPress plugin, according to the plugin’s developer, Janis Elsts. Version 2.35 planted PHP code that created a web shell and a hidden user account, while the clean version 2.36 was also compromised before the developer could regain control of the site.

Version 2.35 was available approximately between 06:00 and 13:00 UTC on September 15, 2026, before it was withdrawn. After discovering the breach, Elsts published version 2.36 at 19:00 UTC on the same day, but the attacker still had access to the site and was also able to tamper with the new release.

The Scope of the Impact Remains Unclear

The developer said that analysis of the update server logs indicates that approximately 230 customers were affected in the first attack, with the malicious version installed on at least 1,500 sites because some customers manage multiple sites. He added that several hundred customers downloaded the plugin during or near the same time period, meaning the final number could be higher, particularly for version 2.36, which was compromised after it was published.

Admin Menu Editor Pro allows WordPress administrators to customize dashboard menus, hide plugins from certain users, configure permissions by role, and create redirects when users log in and out. The free version of Admin Menu Editor, which is installed on more than 300,000 sites, does not appear to be affected according to the available information.

What Should Be Checked?

Anyone who installed versions 2.35 or 2.36 should check for the following indicators of compromise:

  • The file includes/wp-user-consent.php inside the admin-menu-editor-pro directory.
  • A new /wp-content/object-cache/ directory.
  • A user whose name begins with wp_ in the wp_users table, which may not appear in the WordPress dashboard.
  • Options with names following the pattern wp_ocache* in the wp_options table.

What Changes in Practice for Site Administrators?

The developer removed the malicious updates and published a static page explaining the incident and verification steps, but he took the site offline after the investigation concluded that the attacker may have had root-level privileges on the server. This point is important because updating the plugin to a new version may not be sufficient if the distribution channel itself was compromised.

Version 2.34 is believed to be safe. The developer recommends restoring the site from a trusted backup dating from before September 14 as the most reliable action. If restoration is not possible, the recommendations include deleting the plugin, the /wp-content/object-cache/ directory, and the database entries associated with the account and options mentioned above. The source does not establish that these steps alone remove all traces of the breach in cases where the site was subjected to additional modifications; therefore, reviewing the site’s integrity and backups remains an open issue for those affected.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news