Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin have affected 1,500 WordPress sites.
Intelligence analysis by Qwen 2.5 (3B)

A threat actor compromised the Admin Menu Editor Pro plugin, leading to the installation of a hidden user account on 1,500 WordPress sites.
A bad person tricked a website and made a bad update. This update let them hide a secret account on 1,500 websites.
Analysis
{"heading_1":"The Incident","content_1":"On September 14, 2026, a threat actor compromised the adminmenueditor.com website and uploaded a malicious version of the Admin Menu Editor Pro plugin.","content_2":"The malicious version included an includes/wp-user-consent.php file that created a hidden user account on affected sites.","content_3":"The developer, Janis Elsts, removed the malicious update and pushed a clean version 2.36, but the hacker still had access to the website and compromised the new version."}
Key points
- Malicious Admin Menu Editor Pro plugin affected 1,500 WordPress sites
- Developer removed malicious update and pushed clean version
- Customers need to check for signs of compromise and take action if necessary
Customers can check for signs of compromise and restore their sites from a safe backup if possible.
If a safe backup is not available, customers may need to delete the plugin and compromised files.



