← Back to Feed
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
September 15, 2026 · BleepingComputer · Severity: MEDIUM
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account.
Key Takeaways
- A malicious WordPress plugin called Admin Menu Editor Pro has been discovered backdooring over 1,500 websites through a supply chain attack on the plugin repository.
- The compromised plugin injects malicious code that creates unauthorized admin accounts and exfiltrates site data to attacker-controlled servers.
- WordPress site administrators should audit their installed plugins and remove any instances of Admin Menu Editor Pro immediately, then rotate all admin credentials.