IT

Malicious Admin Menu Editor Pro Plugin Backdoors 1,500 WordPress Sites

A compromise of the Admin Menu Editor Pro plugin maintainer's website led to malicious updates creating hidden admin accounts across thousands of WordPress sites.

·1 min read
Malicious Admin Menu Editor Pro Plugin Backdoors 1,500 WordPress Sites

The widely used Admin Menu Editor Pro plugin for WordPress has been targeted in a supply chain attack. Threat actors successfully compromised the developer's official website and pushed malicious updates to unsuspecting users.

Investigations revealed that compromised versions were distributed to over 200 customers, affecting approximately 1,500 WordPress websites in total. Once installed, the modified plugin automatically created a hidden administrator account within the target site.

This security breach highlights the ongoing risks associated with third-party plugin ecosystems. Even paid and trusted extensions can become vectors for unauthorized access if the original vendor's infrastructure is breached.

Security experts advise web administrators to audit their WordPress installations immediately, check for rogue administrator accounts, and apply necessary patches. Vigilance regarding software updates remains critical for maintaining web security.

For developers and site administrators globally, this incident serves as a crucial reminder to enforce strict monitoring and perform regular security checks on all active plugins and extensions.

#WordPress#Cybersecurity#Plugins#Admin Menu Editor Pro#Malware#BleepingComputer

Related articles