Malicious WordPress Plugin Update Compromises Security for Over 200 Users
More than 200 clients have unwittingly been exposed to a perilous version of the Admin Menu Editor Pro plugin for WordPress following a breach of the maintainer’s website.
This security incident allowed a threat actor to deploy updates that established a clandestine user account on affected installations.
According to developer Janis Elsts, the unauthorized intrusion occurred on Monday when an assailant accessed the adminmenueditor.com site and uploaded version 2.35 as an update for the Pro version of the plugin.
This update contained a malicious file—includes/wp-user-consent.php—that initiated a web shell on compromised websites.
Upon realizing the breach, Elsts expeditiously removed the harmful update and issued a sanitized version, 2.36, later that same day at 19:00 UTC. Nonetheless, the hacker retained access to the site and subsequently contaminated the new version as well.
Admin Menu Editor Pro constitutes the premium variant of Admin Menu Editor, a widely-utilized WordPress plugin present on over 300,000 sites.
This tool enables administrators to customize their Dashboard menus, conceal plugins from various users, set access limitations per role, and establish login/logout redirections.
Communicating with BleepingComputer, Elsts noted that the nefarious Admin Menu Editor Pro version 2.35 was accessible on the official website for a period of approximately seven hours, from about 06:00 to 13:00 UTC. It was during this time that the insidious PHP code was deployed, creating a hidden user account.
As per the developer’s insights, at least 230 customers installed the harmful update across 1,500 sites. However, Elsts cautions that this figure may be an underrepresentation, as pinpointing the number of users operating a compromised version 2.36 of the plugin is fraught with uncertainty.
“An analysis of the update server logs indicates that approximately 230 customers were initially compromised. The harmful version infiltrated at least 1,500 sites, with often multiple sites per customer,” stated Elsts in his commentary to BleepingComputer.
He further elaborated, “Several hundred additional customers downloaded the plugin during or near the pertinent timeframe, and could likewise be at risk.”
The investigation implies that the attacker potentially gained root-level server access, compelling Elsts to take preventive measures by decommissioning the website until a secure restoration could be assured.
To inform users, Elsts has published a static page detailing the incident and providing guidance for checking potential impacts, alongside recommendations for restoring compromised sites to a secure state.
Individuals who installed versions Admin Menu Editor Pro 2.35 and 2.36 are advised to inspect their systems for the following indicators of a breach:
- The presence of includes/wp-user-consent.php within the admin-menu-editor-pro directory
- A newly created /wp-content/object-cache/ directory
- A user entry beginning with wp_ in the wp_users table, which might be obscured from the WordPress dashboard
- Options labeled as wp_ocache* in the wp_options table
Version 2.34 is deemed secure, and the free variant of Admin Menu Editor does not appear to have been compromised.
Elsts emphasizes that the most effective remedy is to restore any affected site from a secure backup established before September 14.
If such recovery is unattainable, the developer advises removing the plugin, the “/wp-content/object-cache/” directory, and the aforementioned database entries.

The Admin Menu Editor WordPress plugin developer has assured that the incident was confined to their infrastructure and has expressed sincere apologies to the adversely impacted customers.
Source link: Bleepingcomputer.com.




