:

WORDPRESS PLUGIN BACKDOOR HITS 1,500+ SITES

INDUSTRY DESK1 MIN READ
TUE, SEP 15, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A compromised Admin Menu Editor Pro plugin distributed malicious updates to over 200 customers, creating hidden administrator accounts on approximately 1,500 WordPress sites. A threat actor gained access to the plugin maintainer's website and pushed weaponized versions.

The Admin Menu Editor Pro plugin, used to customize WordPress admin interfaces, became a vector for widespread compromise after an attacker breached the developer's infrastructure. Malicious updates injected code that established hidden user accounts, granting unauthorized administrative access to affected installations. The compromise went undetected until discovered, with the full scope still being assessed. WordPress site owners using Admin Menu Editor Pro should immediately update to patched versions and audit user accounts for unauthorized entries. Security researchers recommend verifying plugin integrity and monitoring for suspicious administrative activity. The incident highlights risks in the WordPress plugin ecosystem, where compromised legitimate tools can bypass security defenses. Site administrators should implement robust access controls and maintain regular backups as protective measures against plugin-based attacks.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A security researcher demonstrated a critical vulnerability in Baseten's infrastructure, obtaining full administrative access to the company's production GitHub account in under half an hour. The exploit highlights widespread risks in how companies manage authentication tokens.

JUST NOWDev Desk

Acronis has disclosed a high-severity Linux privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that attackers are actively exploiting in the wild.

JUST NOWSecurity Desk

A significant breach of America's driver's license data has exposed millions of citizens to identity theft and security threats. Experts warn the incident represents a critical vulnerability in national security infrastructure.

JUST NOWSecurity Desk

Storing your driver's license in Apple Wallet or Google Wallet offers convenience, but carries significant privacy and security implications worth understanding before you make the switch.

3H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.