Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Compromised Admin Menu Editor Pro update server distributed backdoored plugin versions installing web shells and hidden admin accounts on roughly 1,500 WordPress sites.
A threat actor with root-level access to adminmenueditor.com pushed trojanized Admin Menu Editor Pro versions 2.35 and 2.36 containing includes/wp-user-consent.php, which installed a web shell and created a hidden wp_-prefixed user account. At least 230 customers and roughly 1,500 sites installed the malicious update, with several hundred more downloads possibly affected. Developer Janis Elsts took the site offline after the attacker recompromised the clean 2.36 release; version 2.34 and the free plugin are believed unaffected.
- Trojanized versions 2.35 and 2.36 installed web shells via wp-user-consent.php
- About 230 customers and at least 1,500 sites affected
- Attacker had root-level access and compromised the clean 2.36 release too
- Recommended fix is restoring from a pre-September 14 backup
- Compromise indicators include wp_ user, wp_ocache* options, object-cache directory
Full article535 words · extracted from bleepingcomputer.com · click to collapse

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account.
Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites.
After noticing the intrusion, Elsts removed the malicious update and pushed a clean version 2.36 on the same day at 19:00 UTC. However, the hacker still had access to the website and compromised the new version, too.
Admin Menu Editor Pro is the premium version of Admin Menu Editor, a WordPress plugin present on more than 300,000 sites that allows administrators to customize their Dashboard menu, hide plugins from other users, set per-role access limits, and create login/logout redirects.
Elsts told BleepingComputer that the malicious Admin Menu Editor Pro version 2.35 was available on the official website from approximately 06:00 to 13:00 UTC. The malicious PHP code it contained also created a hidden user account.
According to the developer, at least 230 customers installed the malicious update on 1,500 sites. However, Elsts warns that the victim count could be larger since it is difficult to determine the number of customers running a trojanized version 2.36 of the plugin.
"Based on analysis of update server logs, approximately 230 customers were affected in the initial attack. The malicious version was installed at least 1500 sites (often multiple sites per customer)," Elsts told BleepingComputer.
"Several hundred additional customers downloaded the plugin in or near the relevant time window, and could have also been affected," the developer added.
The investigation indicates that the attacker likely had root-level server access, so Elsts decided to protect customers by taking the website offline until it could be restored with confidence.
Currently, Ests published a static page with details about the incident and what customers can do to check if they are affected, along with recommendations to restore compromised websites to a safe state.
Anyone who installed versions Admin Menu Editor Pro 2.35 and 2.36 should check for the following signs of compromise:
- includes/wp-user-consent.php in the admin-menu-editor-pro directory
- A new /wp-content/object-cache/ directory
- A user beginning with wp_ in the wp_users table, which may be hidden from the WordPress dashboard
- Options named like wp_ocache* in the wp_options table
Version 2.34 is believed to be clean, and the free version of Admin Menu Editor does not appear to be affected.
Elsts says that the most reliable fix is to restore a compromised site from a safe backup before September 14. If this is not possible, the developer recommends deleting the plugin, the "/wp-content/object-cache/" directory, and the above database entries.
The developer of the Admin Menu Editor WordPress plugin said the incident was limited to its infrastructure and apologized to affected customers.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/