Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
A compromised Admin Menu Editor Pro website pushed malicious plugin updates to WordPress customers, creating hidden user accounts and deploying a web shell on affected sites. The incident impacted at least 230 customers across about 1,500 sites, and users of versions 2.35 and 2.36 are urged to check for signs of compromise and restore from a safe backup if possible. #AdminMenuEditorPro #JanisElsts #WordPress

Keypoints

  • The Admin Menu Editor Pro maintainer’s website was compromised and used to distribute malicious updates.
  • Version 2.35 installed a web shell and created a hidden user account on affected WordPress sites.
  • The attacker also compromised the clean 2.36 release after the initial malicious update was removed.
  • At least 230 customers and about 1,500 sites were affected, with the real impact possibly higher.
  • Users should look for wp-user-consent.php, /wp-content/object-cache/, hidden wp_ users, and wp_ocache* options.

Read More: https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/