Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Executive Summary
Malicious versions of the Admin Menu Editor Pro plugin for WordPress were distributed to over 200 customers after a threat actor compromised the maintainer’s website and pushed updates that added a hidden user account. The compromised updates created backdoors in more than 1,500 WordPress sites, allowing attackers to gain unauthorized access and potentially exfiltrate data or further compromise the sites.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-15T20:34:15+00:00 - Category: threat-intel
Original Description: Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
"Setting an example is not the main means of influencing another, it is the only means."
— Albert Einstein