chiprook
← Security
SecuritySeptember 16, 2026, 03:34

Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Hackers breached the developer's site for Admin Menu Editor Pro and released versions 2.35 and 2.36 containing a web shell and a hidden account. According to developer Janis Elsts, about 230 clients installed the malicious version on 1,500 sites; the site is offline until restoration.

Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
#WordPress#AdminMenuEditor
Read next
Security

WordPress Click2Shell flaw lets hackers run PHP on the server

Security

ZoomEye: Over 239,000 Citrix NetScaler Gateways Exposed Amid SAML Bypass

Security

Microsoft and Google take down $66 million RedVDS cybercrime marketplace

Security

Contagious Interview Campaign Hits 30,000 Devices, Steals $10.71M in Crypto