WordPress Admin Menu Editor Pro Backdoor Infected 1,500 Sites
A malicious version of the Admin Menu Editor Pro plugin for WordPress was distributed to more than 200 customers after a threat actor compromised the plugin developer’s website and pushed an update that created hidden administrator accounts.
Developer Janis Elsts said an unauthorized person accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the Pro version of the plugin. The update included an include/wp-user-consent.php file that installed a web shell on affected websites.
After Elsts discovered the intrusion, the malicious update was removed and a clean version, 2.36, was released at 19:00 UTC the same day. However, the attacker continued accessing the website and compromising newly released versions.
Admin Menu Editor Pro is a WordPress plugin installed on more than 300,000 sites. It allows administrators to customize dashboard menus, hide plugins from other users, restrict access by role, create login and logout redirects, and perform other administrative tasks.
Elsts told BleepingComputer that the malicious Admin Menu Editor Pro version 2.35 was available on the official website from approximately 06:00 to 13:00 UTC. The malicious PHP code also created hidden WordPress user accounts.
Admin Menu Editor Pro attack affected at least 1,500 sites
According to the developer, at least 230 customers installed the malicious update across 1,500 sites. However, the total number of affected websites could be higher because it remains difficult to determine how many customers installed a trojanized version 2.36 of the plugin.
“According to our analysis of update server logs, approximately 230 customers were affected in the initial attack. The malicious version was installed on at least 1,500 sites, often multiple sites per customer,” Elsts told BleepingComputer.
“Hundreds of additional customers downloaded the plugin at or near the relevant times and may have been affected,” the developer added.
An investigation indicated that the attacker likely had root-level access to the server. Elsts therefore took the website offline to protect customers until it could be reliably restored.
A static page from the developer provides additional details about the incident, including how customers can determine whether they are affected and recommendations for restoring compromised websites to a secure state.
How to check for the WordPress plugin backdoor
Anyone who installed Admin Menu Editor Pro versions 2.35 or 2.36 should check for the following indicators of compromise:
- The
admin-menu-editor-prodirectory contains/wp-user-consent.php. - A new
/wp-content/object-cache/directory is present. - The
wp_userstable contains users whose names start withwp_. These accounts may not appear in the WordPress dashboard. - The
wp_optionstable contains options with names such aswp_ocache*.
Version 2.34 is considered clean, and the free version of Admin Menu Editor does not appear to be affected.
How to remove the Admin Menu Editor Pro malware
According to Elsts, the most reliable solution is to restore the compromised website from a secure backup created by September 14. If that is not possible, the developer recommends deleting the plugin, removing the /wp-content/object-cache/ directory, and deleting the related database entry.
The developer of the Admin Menu Editor WordPress plugin said the incident was limited to its infrastructure and apologized to affected customers.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



