bleeping-computer · Crawled Sep 16, 2026

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

2 IoCs
Read original article ↗

AI Summary

A threat actor compromised the maintainer's website for the Admin Menu Editor Pro WordPress plugin and distributed malicious updates (versions 2.35 and 2.36), which backdoored approximately 1,500 sites. The backdoor created a hidden user account and installed a web shell via a malicious file named wp-user-consent.php. The attacker had likely gained root-level access to the server, prompting the developer to take the site offline and issue cleanup guidance. Customers are advised to check for specific indicators of compromise and restore from clean backups.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename includes/wp-user-consent.php Details →
Filename /wp-content/object-cache/ Details →