Home / Sep 16, 2026 / Story
0
#7 BleepingComputer general September 15, 2026 at 20:34 UTC

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

By Bill Toulas

AI Summary

A threat actor compromised the maintainer's website for the Admin Menu Editor Pro WordPress plugin and pushed malicious updates to over 200 customers, resulting in backdoored installations across approximately 1,500 WordPress sites with hidden admin accounts created for persistent access. This supply-chain-style attack on a premium plugin highlights the risk of automatic plugin updates in WordPress environments where the upstream vendor's own infrastructure is compromised.

Relevance score: 85.0/100

# More from September 16