← Blog · · df00tech

Compromised Admin Menu Editor Pro Updates Backdoored Over 1,500 WordPress Sites

security-news campaign

What Happened

According to BleepingComputer, a threat actor compromised the maintainer's website for the Admin Menu Editor Pro WordPress plugin and used that access to push malicious plugin updates. The tainted updates reached more than 200 customers and, per the report, resulted in roughly 1,500 WordPress sites being backdoored. The malicious update created a hidden administrator-level user account on affected sites, giving the attacker persistent access.

Why It Matters for Defenders

This is a software supply chain attack against a trusted update channel rather than a vulnerability in WordPress core. Any organization running Admin Menu Editor Pro — or relying on premium/commercial WordPress plugins with auto-update mechanisms — inherits risk from the plugin vendor's own security posture. A compromised hidden admin account can be used for further exploitation: content tampering, malware/spam injection, credential harvesting, or use of the site as infrastructure for follow-on campaigns. Because the account was created via a legitimate-looking update, it may not trigger the scrutiny a manually added admin account would.

What Defenders Should Watch For

  • Audit the WordPress users table for unexpected administrator accounts, especially ones created around the timeframe the malicious updates were distributed (mid-September 2026 per the report).
  • Review Admin Menu Editor Pro plugin version history and update logs on any site where it's installed; compare against the vendor's official changelog for discrepancies.
  • Hunt for anomalous wp-admin logins, new application passwords, or REST API user-creation events correlated with plugin update activity.
  • Check outbound connections and scheduled tasks/cron jobs on WordPress hosts for signs of a webshell or secondary payload dropped after the hidden account was created.
  • As a mitigation, pin plugin updates and review changes manually where feasible, and rotate credentials/API keys on any site confirmed to run the plugin.

Developing Intel

This write-up is based on a single vendor/media report and details may evolve as more information becomes available — including the exact compromise vector at the maintainer's site and the full scope of affected installs. For the latest, see the original coverage at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.