CuraSec

Act active

Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

2026-09-16 15:25 UTC · BleepingComputer · read the source ↗ #supply-chain#wordpress#backdoor
  • Engineer — Act: If you distribute or run WordPress with Admin Menu Editor Pro, audit all admin-level user accounts immediately for hidden/unauthorized entries and remove or replace the plugin with a verified clean version.
  • SOC/IR — Act: Sweep WordPress admin user tables across managed estates for accounts created after plugin update dates; hunt for unexpected privileged-user creation events in web application logs correlated with this plugin’s presence.
  • Leader — Learn: A small-scale but clean example of plugin supply-chain compromise via maintainer-site takeover; useful context for vendor/third-party software risk discussions, but scale (~200 customers) does not rise to board-level action unless your org runs this specific plugin.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.