$ techbeacon▋
Darkweb

Supply‑Chain Breach of Admin Menu Editor Pro Puts Over 1,500 WordPress Sites at Risk

Supply‑Chain Breach of Admin Menu Editor Pro Puts Over 1,500 WordPress Sites at Risk

A malicious variant of the popular Admin Menu Editor Pro plugin has been used to infiltrate more than 1,500 WordPress installations after threat actors compromised the plugin maintainer's website and pushed tainted updates that silently created a hidden administrative account.

The intrusion was first reported by security outlet BleepingComputer, which traced the malicious code to a series of updates delivered to over 200 paying customers of the plugin. Those customers, in turn, redistributed the compromised version to downstream sites that rely on the same plugin for customizing their WordPress admin menus, expanding the attack surface to well over a thousand sites.

Admin Menu Editor Pro is a premium tool that allows site owners to rearrange, rename, or hide menu items in the WordPress dashboard without editing code. Because it operates with elevated privileges, the plugin is widely installed on business and e‑commerce sites that need granular control over backend navigation. The compromised distribution channel meant that the malicious code reached sites that trusted the plugin’s official source.

Technical analysis of the injected payload shows that the update added a concealed user account with administrator rights. The account does not appear in the standard user list, making detection difficult for site owners. Once active, the hidden account can be used to log in remotely, upload additional malware, exfiltrate data, or alter site content, effectively handing full control of the affected WordPress installation to the attacker.

Security experts advise administrators to audit their user tables for unexpected accounts, revoke any unknown administrator privileges, and replace the compromised plugin with a clean copy obtained directly from the vendor’s verified repository. Changing all associated passwords, enabling two‑factor authentication, and scanning the file system with reputable malware scanners are also recommended steps to limit further damage.

The incident highlights the growing risk of supply‑chain attacks within the WordPress ecosystem, where thousands of plugins are maintained by small teams or individual developers. Researchers stress the importance of verifying the integrity of plugin updates through checksums or digital signatures and suggest that hosting providers enforce stricter monitoring of core and plugin files. Ongoing investigations aim to identify the attackers and assess whether additional plugins or themes were similarly affected.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related