Incident
Published 2026-09-15
Verified 2026-09-19

Admin Menu Editor Pro: compromised update channel backdoors ~1,500 WordPress sites (versions 2.35/2.36)

Developer Janis Elsts (adminmenueditor.com) reports that on 14 September 2026 an attacker gained access to the plugin's distribution site and pushed malicious Admin Menu Editor Pro updates. Version 2.35 (available ~06:00–13:00 UTC) dropped includes/wp-user-consent.php (web shell) and created a hidden wp_-prefixed user; a same-day clean 2.36 push was also compromised while the attacker retained access. Update-server logs: ~230 customers, malicious build installed on at least 1,500 sites (multiple sites per customer); several hundred more downloads in the window may be affected. Free Admin Menu Editor and 2.34 believed clean. IoCs per developer: includes/wp-user-consent.php under admin-menu-editor-pro; new /wp-content/object-cache/; wp_ users hidden from the dashboard; wp_ocache* options. Remediation: restore from a backup before 14 Sep 2026, or remove the plugin, delete /wp-content/object-cache/, and purge the listed DB artefacts; site sales/updates offline pending rebuild. Primary: developer incident notice; wire: BleepingComputer 15 Sep.

Product
Admin Menu Editor Pro (WordPress premium plugin)
Versions
Malicious 2.35 and compromised 2.36; 2.34 and free edition believed clean
Exploited in Australia?
unknown
Patch to
Do not run 2.35/2.36 from the compromised channel; restore pre-14 Sep backup or remove plugin + object-cache dir + wp_ / wp_ocache* artefacts per developer guidance; wait for rebuilt distribution

Primary: Admin Menu Editor — developer incident notice (site offline; 14 Sep 2026) · Vendor: adminmenueditor.com (maintainer) · BleepingComputer — Admin Menu Editor Pro supply-chain backdoor (15 Sep 2026)

breaches cloud