← Back to Feed

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

September 15, 2026 · BleepingComputer · Severity: MEDIUM

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account.

Key Takeaways

  • A malicious WordPress plugin called Admin Menu Editor Pro has been discovered backdooring over 1,500 websites through a supply chain attack on the plugin repository.
  • The compromised plugin injects malicious code that creates unauthorized admin accounts and exfiltrates site data to attacker-controlled servers.
  • WordPress site administrators should audit their installed plugins and remove any instances of Admin Menu Editor Pro immediately, then rotate all admin credentials.
☕ Buy a Coffee