Malicious Admin Menu Editor Pro Plugin Backdoors 1,500 WordPress Sites
ID: 5fed70d6-3224-5304-8fd7-2a47c20904b8
STIX ID: report--5fed70d6-3224-5304-8fd7-2a47c20904b8
Feed Name: CosmicBytez Labs
A compromised update server for the premium WordPress plugin Admin Menu Editor Pro was used to distribute trojanized releases (v2.35 and a re-compromised v2.36) that installed a disguised web shell (includes/wp-user-consent.php), created hidden admin accounts and persisted via object-cache/options artifacts; at least 230 customers and roughly 1,500 sites are confirmed affected and site owners should check the listed IoCs, restore from clean backups if possible, rotate credentials, and avoid updating until the update infrastructure is verified secured.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
