A malicious version of the Admin Menu Editor Pro WordPress plugin was distributed to customers after attackers gained access to the plugin developer’s website and pushed a compromised update containing a hidden backdoor.
The incident affected the premium version of Admin Menu Editor Pro, a plugin used by WordPress administrators to customize dashboard menus, control access based on user roles, and manage login and logout redirects. The free version of the plugin does not appear to have been affected.
According to developer Janis Elsts, an unauthorized party gained access to the adminmenueditor.com website and uploaded version 2.35 of the Pro plugin as an update. The malicious release contained a PHP file named includes/wp-user-consent.php, which installed a web shell on websites where the compromised update was installed.
The developer discovered the intrusion and removed version 2.35 before releasing a clean version 2.36 at 19:00 UTC on the same day. However, the attacker still had access to the website and managed to compromise the new version as well.
Version 2.35 was available on the official website for several hours, from around 06:00 to 13:00 UTC. Besides the web shell, the malicious code also created a hidden WordPress user account.
The developer estimates that around 230 customers installed the malicious update, with the compromised versions reaching at least 1,500 WordPress sites. The actual number could be higher because several hundred additional customers downloaded the plugin around the same period and some may have installed the compromised version 2.36.
The investigation also indicates that the attacker may have obtained root-level access to the plugin’s server. Because of the potential impact, Elsts took the website offline while working to restore the infrastructure safely.
Website owners who installed Admin Menu Editor Pro versions 2.35 or 2.36 are advised to check their sites for signs of compromise. One indicator is the presence of includes/wp-user-consent.php inside the Admin Menu Editor Pro directory. Other signs include a new /wp-content/object-cache/ directory, a suspicious user beginning with wp_ in the wp_users database table, and database options with names resembling wp_ocache*.
Version 2.34 is believed to be clean, while the free Admin Menu Editor plugin is not currently believed to have been affected by the incident.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
For websites that may have been compromised, the developer says the most reliable recovery method is to restore the site from a known-safe backup created before September 14. If that isn’t possible, customers are advised to remove the affected plugin, delete the /wp-content/object-cache/ directory, and remove the suspicious database entries associated with the compromise.



