Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites | HappeningNow.news

Cybersecurity · 3 views

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account.

Source Summary Published 1h 00m ago Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 3 Community interest
Brief read Under 1 min brief 75 words

Summary

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites.

Read original at Bleepingcomputer

Coverage Context

Part of Wordpress coverage 59 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page