Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Casetify Promo Codes | 15% Off September 2026

    September 16, 2026

    Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

    September 16, 2026

    XRP sinks 10% as the Clarity Act fails and bitcoin slides toward $76,000

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Casetify Promo Codes | 15% Off September 2026
    • Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
    • XRP sinks 10% as the Clarity Act fails and bitcoin slides toward $76,000
    • Since US intervention, Venezuela’s illegal mining crisis has only worsened, critics say
    • It’s my self-care hack of the year: I quit our local veg box scheme, and set my mind free | Rhiannon Lucy Cosslett
    • Did Chinese government warn people not to respond to aliens and call UN hotline instead?
    • Gaza residential building collapses, six families reportedly trapped | Gaza News
    • To understand the threat to our real democracy, watch Putin’s fake one | Rafael Behr
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 16, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account.

    Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites.

    After noticing the intrusion, Elsts removed the malicious update and pushed a clean version 2.36 on the same day at 19:00 UTC. However, the hacker still had access to the website and compromised the new version, too.

    Admin Menu Editor Pro is the premium version of Admin Menu Editor, a WordPress plugin present on more than 300,000 sites that allows administrators to customize their Dashboard menu, hide plugins from other users, set per-role access limits, and create login/logout redirects.

    Elsts told BleepingComputer that the malicious Admin Menu Editor Pro version 2.35 was available on the official website from approximately 06:00 to 13:00 UTC. The malicious PHP code it contained also created a hidden user account.

    According to the developer, at least 230 customers installed the malicious update on 1,500 sites. However, Elsts warns that the victim count could be larger since it is difficult to determine the number of customers running a trojanized version 2.36 of the plugin.

    “Based on analysis of update server logs, approximately 230 customers were affected in the initial attack. The malicious version was installed at least 1500 sites (often multiple sites per customer),” Elsts told BleepingComputer.

    “Several hundred additional customers downloaded the plugin in or near the relevant time window, and could have also been affected,” the developer added.

    The investigation indicates that the attacker likely had root-level server access, so Elsts decided to protect customers by taking the website offline until it could be restored with confidence.

    Currently, Ests published a static page with details about the incident and what customers can do to check if they are affected, along with recommendations to restore compromised websites to a safe state. 

    Anyone who installed versions Admin Menu Editor Pro 2.35 and 2.36 should check for the following signs of compromise:

    • includes/wp-user-consent.php in the admin-menu-editor-pro directory
    • A new /wp-content/object-cache/ directory
    • A user beginning with wp_ in the wp_users table, which may be hidden from the WordPress dashboard
    • Options named like wp_ocache* in the wp_options table

    Version 2.34 is believed to be clean, and the free version of Admin Menu Editor does not appear to be affected.

    Elsts says that the most reliable fix is to restore a compromised site from a safe backup before September 14. If this is not possible, the developer recommends deleting the plugin, the “/wp-content/object-cache/” directory, and the above database entries.

    The developer of the Admin Menu Editor WordPress plugin said the incident was limited to its infrastructure and apologized to affected customers.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Admin Backdoors Editor Malcious menu Plugin Pro sites WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

    Acronis warns of actively exploited flaw in its cPanel backup plugin

    Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

    Exein Secures $270M at $1.7B Valuation for Physical AI Security

    Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Casetify Promo Codes | 15% Off September 2026

    September 16, 2026

    Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

    September 16, 2026

    XRP sinks 10% as the Clarity Act fails and bitcoin slides toward $76,000

    September 16, 2026

    Since US intervention, Venezuela’s illegal mining crisis has only worsened, critics say

    September 16, 2026
    Latest Posts

    Two new compounds could reveal hidden drivers of Alzheimer’s disease

    August 4, 2026

    Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Casetify Promo Codes | 15% Off September 2026

    September 16, 2026

    Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

    September 16, 2026

    XRP sinks 10% as the Clarity Act fails and bitcoin slides toward $76,000

    September 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.