← Back to Tech & Science

Malicious Update to WordPress Plugin Compromises Over 1,500 Sites

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

A threat actor compromised the official website for the Admin Menu Editor Pro WordPress plugin on Sept. 15, 2026, distributing malicious software updates that infected more than 1,500 websites globally. The attack involved the insertion of code designed to create hidden administrative user accounts and install web shells, granting unauthorized actors persistent access to affected systems.

The breach occurred when the maintainer's website was infiltrated, allowing the attacker to push a compromised version of the popular plugin to users who had enabled automatic updates. Security researchers identified the malicious payload shortly after the distribution began. The rogue update did not merely alter functionality; it established backdoors that allowed remote command execution and data exfiltration without the site owners' knowledge.

Admin Menu Editor Pro is widely used by website administrators to customize the backend interface of WordPress sites, a platform powering a significant portion of the internet's web presence. Because the plugin holds high-level permissions within the WordPress ecosystem, the compromise of its update channel allowed the malicious code to execute with elevated privileges on every site that downloaded the infected version.

The attack vector relied entirely on the trust users placed in the official distribution channel. By compromising the maintainer's infrastructure, the threat actor bypassed standard security checks that typically flag suspicious code from unofficial sources. The hidden user accounts created by the malware were designed to evade detection, appearing as legitimate system entries while providing a foothold for further exploitation.

Site administrators who received the update on or before Sept. 15 are advised to immediately disconnect their servers from the internet, remove the compromised plugin version, and audit all user accounts for unauthorized additions. The web shells installed by the malware remain active until manually removed, posing an ongoing risk of data theft or the use of infected sites as part of a larger botnet.

The motive behind the attack remains unclear. No ransom demands have been issued, and no specific target sectors appear to have been prioritized in the initial wave of infections. The scope of the compromise suggests a broad attempt to maximize the number of vulnerable systems rather than a targeted intrusion against specific organizations.

As of late Tuesday, the plugin maintainer has restored control of their website and is working to issue a clean version of the software. However, the full extent of the damage remains unknown. Questions persist regarding whether the attacker maintained access to the maintainer's infrastructure or if the breach was limited to a single point of entry. Additionally, it is unclear if any data was exfiltrated from the compromised sites before the malicious update was identified and halted.

Discussion

0 / 2000