Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Hackers breached the developer's site for Admin Menu Editor Pro and released versions 2.35 and 2.36 containing a web shell and a hidden account. According to developer Janis Elsts, about 230 clients installed the malicious version on 1,500 sites; the site is offline until restoration.
- Malicious versions 2.35 and 2.36 were available on the official site on September 14
- The update created includes/wp-user-consent.php and a hidden user wp_
- At least 230 clients installed the plugin on 1,500 sites
- Version 2.34 and the free Admin Menu Editor were not affected
Read next
Security