Malicious Backdoors in Admin Menu Editor Pro Plugin Affect 1,500 WordPress Websites

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Malicious WordPress Plugin Update Compromises Security for Over 200 Users

More than 200 clients have unwittingly been exposed to a perilous version of the Admin Menu Editor Pro plugin for WordPress following a breach of the maintainer’s website.

This security incident allowed a threat actor to deploy updates that established a clandestine user account on affected installations.

According to developer Janis Elsts, the unauthorized intrusion occurred on Monday when an assailant accessed the adminmenueditor.com site and uploaded version 2.35 as an update for the Pro version of the plugin.

This update contained a malicious file—includes/wp-user-consent.php—that initiated a web shell on compromised websites.

Upon realizing the breach, Elsts expeditiously removed the harmful update and issued a sanitized version, 2.36, later that same day at 19:00 UTC. Nonetheless, the hacker retained access to the site and subsequently contaminated the new version as well.

Admin Menu Editor Pro constitutes the premium variant of Admin Menu Editor, a widely-utilized WordPress plugin present on over 300,000 sites.

This tool enables administrators to customize their Dashboard menus, conceal plugins from various users, set access limitations per role, and establish login/logout redirections.

Communicating with BleepingComputer, Elsts noted that the nefarious Admin Menu Editor Pro version 2.35 was accessible on the official website for a period of approximately seven hours, from about 06:00 to 13:00 UTC. It was during this time that the insidious PHP code was deployed, creating a hidden user account.

As per the developer’s insights, at least 230 customers installed the harmful update across 1,500 sites. However, Elsts cautions that this figure may be an underrepresentation, as pinpointing the number of users operating a compromised version 2.36 of the plugin is fraught with uncertainty.

“An analysis of the update server logs indicates that approximately 230 customers were initially compromised. The harmful version infiltrated at least 1,500 sites, with often multiple sites per customer,” stated Elsts in his commentary to BleepingComputer.

He further elaborated, “Several hundred additional customers downloaded the plugin during or near the pertinent timeframe, and could likewise be at risk.”

The investigation implies that the attacker potentially gained root-level server access, compelling Elsts to take preventive measures by decommissioning the website until a secure restoration could be assured.

To inform users, Elsts has published a static page detailing the incident and providing guidance for checking potential impacts, alongside recommendations for restoring compromised sites to a secure state.

Individuals who installed versions Admin Menu Editor Pro 2.35 and 2.36 are advised to inspect their systems for the following indicators of a breach:

  • The presence of includes/wp-user-consent.php within the admin-menu-editor-pro directory
  • A newly created /wp-content/object-cache/ directory
  • A user entry beginning with wp_ in the wp_users table, which might be obscured from the WordPress dashboard
  • Options labeled as wp_ocache* in the wp_options table

Version 2.34 is deemed secure, and the free variant of Admin Menu Editor does not appear to have been compromised.

Elsts emphasizes that the most effective remedy is to restore any affected site from a secure backup established before September 14.

If such recovery is unattainable, the developer advises removing the plugin, the “/wp-content/object-cache/” directory, and the aforementioned database entries.

Blue circle icon with two interlocking plugs, one featuring the WordPress logo, symbolizing WordPress plugins or connectivity.

The Admin Menu Editor WordPress plugin developer has assured that the incident was confined to their infrastructure and has expressed sincere apologies to the adversely impacted customers.

Source link: Bleepingcomputer.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading