{"id":7420,"date":"2026-09-15T21:05:16","date_gmt":"2026-09-15T21:05:16","guid":{"rendered":"https:\/\/lockitsoft.com\/?p=7420"},"modified":"2026-09-15T21:05:16","modified_gmt":"2026-09-15T21:05:16","slug":"malcious-admin-menu-editor-pro-plugin-backdoors-1500-wordpress-sites","status":"publish","type":"post","link":"https:\/\/lockitsoft.com\/?p=7420","title":{"rendered":"Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites"},"content":{"rendered":"<p>The digital supply chain powering the world\u2019s most popular content management system has suffered a significant breach, as malicious actors successfully compromised the official distribution infrastructure of Admin Menu Editor Pro, a prominent WordPress plugin. The security incident, which unfolded earlier this week, resulted in thousands of website installations being trojanized with hidden administrative backdoors and web shells. Security researchers and the plugin\u2019s developer have confirmed that threat actors gained unauthorized access to the developer&#8217;s server environment, systematically injecting malicious code into freshly released software updates. This sophisticated cyberattack underscores the persistent vulnerabilities inherent in third-party software dependencies and highlights how centralized software distribution channels remain a high-value target for opportunistic and state-sponsored hackers alike.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/lockitsoft.com\/?p=7420\/#Anatomy_of_the_Supply_Chain_Compromise\" >Anatomy of the Supply Chain Compromise<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/lockitsoft.com\/?p=7420\/#Chronology_of_the_Incident\" >Chronology of the Incident<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/lockitsoft.com\/?p=7420\/#Scope_of_Impact_and_Vulnerable_Ecosystem\" >Scope of Impact and Vulnerable Ecosystem<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/lockitsoft.com\/?p=7420\/#Remediation_Protocols_and_Developer_Response\" >Remediation Protocols and Developer Response<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/lockitsoft.com\/?p=7420\/#Broader_Implications_for_WordPress_Security\" >Broader Implications for WordPress Security<\/a><\/li><\/ul><\/nav><\/div>\n<h3><span class=\"ez-toc-section\" id=\"Anatomy_of_the_Supply_Chain_Compromise\"><\/span>Anatomy of the Supply Chain Compromise<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The security breach centered on adminmenueditor.com, the official distribution hub for the professional iteration of the Admin Menu Editor plugin. Janis Elsts, the independent developer behind the utility, identified the unauthorized intrusion after noticing anomalies in software release logs. According to forensic findings, an unidentified threat actor secured root-level access to the hosting infrastructure, enabling them to manipulate software packages distributed directly to paying customers. <\/p>\n<p>Rather than executing a traditional zero-day exploit against WordPress core architecture, the attackers utilized a classic software supply chain vector. By replacing legitimate plugin installation files with backdoored variants, the threat actors effectively turned the developer&#8217;s own update mechanism into a distribution vector for malware. The compromised updates were engineered to quietly slip past standard administrative oversight, embedding malicious scripts directly into the file systems of unsuspecting target websites.<\/p>\n<p>The primary payload of the malicious updates involved the creation of a hidden user account with administrative privileges, alongside the deployment of a persistent web shell located within an obscured directory structure. Specifically, the injected files introduced an unauthorized script labeled <code>includes\/wp-user-consent.php<\/code>, designed to grant remote attackers continuous, unauthenticated control over the host server. Because the plugin itself requires elevated privileges to function and modify dashboard layouts, the presence of these hidden administrative hooks largely went unnoticed by site owners during routine operations.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Chronology_of_the_Incident\"><\/span>Chronology of the Incident<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The sequence of events began on Monday, when unauthorized third-party actors successfully breached the administrative backend of the Admin Menu Editor Pro web infrastructure. Operating with elevated server privileges, the attackers targeted the newly prepared version 2.35 of the plugin, substituting clean source code with a trojanized package. <\/p>\n<ul>\n<li><strong>Monday, 06:00 UTC:<\/strong> The malicious version 2.35 of Admin Menu Editor Pro goes live on the official distribution server, becoming immediately available for download and automated updates by active customers.<\/li>\n<li><strong>Monday, 13:00 UTC:<\/strong> Following initial telemetry analysis and internal alerts, developer Janis Elsts pulls the compromised 2.35 release offline.<\/li>\n<li><strong>Monday, 19:00 UTC:<\/strong> A newly patched version, labeled 2.36, is compiled and published to the update server in an attempt to remediate the vulnerability. However, because the attackers maintained persistent root-level access to the server environment, this subsequent update is also intercepted and trojanized before it can be effectively secured.<\/li>\n<li><strong>Post-19:00 UTC:<\/strong> Recognizing that the threat actor retains active control over the infrastructure, Elsts makes the decision to take the entire adminmenueditor.com domain offline. A static emergency landing page is deployed to provide technical guidance and remediation strategies for impacted site administrators.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Scope_of_Impact_and_Vulnerable_Ecosystem\"><\/span>Scope of Impact and Vulnerable Ecosystem<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Admin Menu Editor Pro is widely utilized by web agencies, enterprise developers, and site administrators to streamline WordPress backend environments. The tool allows managers to customize dashboard navigation menus, restrict specific capabilities on a per-role basis, hide designated plugins from secondary users, and configure custom redirection pathways following user authentication. While the free, open-source variant of the plugin hosted in the official WordPress repository boasts a massive user base exceeding 300,000 active installations, the Pro version is utilized by a smaller, paying customer base consisting primarily of professional web managers overseeing commercial properties.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2026\/06\/18\/WordPress.jpg\" alt=\"Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<p>Initial telemetry and server log evaluations indicate that approximately 230 distinct customer accounts downloaded the malicious version 2.35 during the narrow window it was publicly active. Because many of these professional developers manage multiple client properties under a single developer license, the downstream impact multiplied rapidly. Elsts confirmed that the malicious code was successfully executed and installed across at least 1,500 individual WordPress domains. <\/p>\n<p>Furthermore, the developer has issued warnings regarding the subsequent version 2.36. Because the threat actor managed to subvert the secondary release before administrative access was fully revoked, an undetermined number of additional customers who pulled updates late Monday evening may also be operating compromised environments. Version 2.34 and earlier iterations remain entirely safe and untouched by the breach, while the free version available via WordPress.org was confirmed to be unaffected by the supply chain attack.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Remediation_Protocols_and_Developer_Response\"><\/span>Remediation Protocols and Developer Response<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>In response to the severity of the infrastructure compromise, Janis Elsts opted for a scorched-earth remediation strategy, shutting down the primary domain and associated services while a comprehensive forensic audit is conducted. The developer released a detailed public advisory outlining step-by-step instructions for identifying signs of intrusion and restoring affected servers to a secure, baseline state.<\/p>\n<p>Security analysts emphasize that standard plugin deletion or routine updates will not fully neutralize an active web shell or eradicate a maliciously generated administrator account. Consequently, the remediation guidance highlights several mandatory steps for compromised site operators:<\/p>\n<ol>\n<li><strong>Database Auditing:<\/strong> Administrators must immediately inspect the <code>wp_users<\/code> and <code>wp_usermeta<\/code> tables within their MySQL databases to identify and permanently delete any unauthorized or unfamiliar administrator accounts created during the attack window.<\/li>\n<li><strong>File System Sanitization:<\/strong> Operators are advised to thoroughly check the <code>\/wp-content\/object-cache\/<\/code> directory and remove any unauthorized PHP scripts, backdoors, or residual configuration files left behind by the payload.<\/li>\n<li><strong>Full System Restores:<\/strong> Elsts stresses that the most reliable method of recovery involves rolling back the affected WordPress installation to a verified, clean backup snapshot created prior to the security incident on Monday.<\/li>\n<li><strong>Credential Rotation:<\/strong> All database passwords, hosting control panel credentials, FTP\/SFTP access keys, and WordPress administrator passwords must be systematically updated to prevent re-entry by the persistent threat actor.<\/li>\n<\/ol>\n<h3><span class=\"ez-toc-section\" id=\"Broader_Implications_for_WordPress_Security\"><\/span>Broader Implications for WordPress Security<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This incident serves as a stark reminder of the unique vulnerabilities inherent in the software supply chain of content management systems. While core WordPress software and repository-hosted plugins undergo automated security scans and code reviews, premium commercial plugins distributed independently by third-party developers operate outside these centralized guardrails. When a developer&#8217;s proprietary server infrastructure is compromised, customers lose the protective barrier traditionally afforded by official app store ecosystems.<\/p>\n<p>Cybersecurity experts point out that supply chain attacks targeting content management plugins are an increasingly favored vector for malicious actors seeking mass distribution. By compromising a single administrative portal, attackers can instantly inherit access to hundreds or thousands of high-value business websites, e-commerce platforms, and publishing networks. These compromised nodes are frequently repurposed for malicious activities, including search engine optimization (SEO) spam injection, distributed denial-of-service (DDoS) botnet recruitment, malware distribution, and credential harvesting.<\/p>\n<p>As the digital landscape evolves, web developers and enterprise security architects face mounting pressure to implement rigorous integrity checks, such as cryptographic signature verification for automated software updates, multi-factor authentication for developer portals, and continuous endpoint monitoring. For the victims of the Admin Menu Editor Pro breach, the immediate focus remains on forensic validation and thorough infrastructure cleanup, serving as a cautionary tale for the broader web development community regarding the fragile nature of third-party software trust.<\/p>\n<!-- RatingBintangAjaib -->","protected":false},"excerpt":{"rendered":"<p>The digital supply chain powering the world\u2019s most popular content management system has suffered a significant breach, as malicious actors successfully compromised the official distribution infrastructure of Admin Menu Editor Pro, a prominent WordPress plugin. The security incident, which unfolded earlier this week, resulted in thousands of website installations being trojanized with hidden administrative backdoors &hellip;<\/p>\n","protected":false},"author":12,"featured_media":7419,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[108],"tags":[4064,4067,109,4066,4063,4065,2294,111,110,4068,2753],"class_list":["post-7420","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-protection","tag-admin","tag-backdoors","tag-cybersecurity","tag-editor","tag-malcious","tag-menu","tag-plugin","tag-privacy","tag-security","tag-sites","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/7420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7420"}],"version-history":[{"count":0,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/7420\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/media\/7419"}],"wp:attachment":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7420"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7420"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}