#7
BleepingComputer
general
September 15, 2026 at 20:34 UTC
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
By Bill Toulas
AI Summary
A threat actor compromised the maintainer's website for the Admin Menu Editor Pro WordPress plugin and pushed malicious updates to over 200 customers, resulting in backdoored installations across approximately 1,500 WordPress sites with hidden admin accounts created for persistent access. This supply-chain-style attack on a premium plugin highlights the risk of automatic plugin updates in WordPress environments where the upstream vendor's own infrastructure is compromised.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →