WordPress plugin update compromised, hidden backdoor affects 1,500 sites

Attackers breached the official website of the Admin Menu Editor Pro plugin and pushed malicious updates that installed a web shell and created a hidden admin account on affected WordPress installations. The developer removed the tainted version but the intruders recompromised the replacement, prompting the site to be taken offline. At least 230 customers across 1,500 sites are confirmed affected, with the number possibly higher.
The attack unfolded over roughly seven hours on Monday, with the tainted version 2.35 available from 06:00 to 13:00 UTC before the developer pulled it. After pushing a supposedly clean 2.36 replacement, the intruders—who likely held root-level server access—compromised that version as well, forcing the maintainer to take the entire site offline. The malicious payload planted a web shell via an includes/wp-user-consent.php file and created a hidden administrator account beginning with "wp_" in the database, along with suspicious cache directories and option entries. The developer has published indicators of compromise and recommends restoring from backups dated before September 14, as version 2.34 is believed clean and the free plugin tier appears unaffected.
This incident could affect thousands of website operators who trusted a legitimate plugin update channel, demonstrating how supply-chain attacks can turn routine maintenance into a security liability. Site owners may face data theft, defacement, or further malware distribution through their compromised infrastructure, while their visitors could be exposed to malicious content. The hidden admin account and web shell suggest persistent access, meaning cleanup may require full restoration rather than simple patching. Smaller businesses without dedicated security teams are especially vulnerable, as they may lack the expertise to detect or remediate such sophisticated compromises.