Executive Summary
In September 2026, an unidentified threat actor compromised the official website of Admin Menu Editor Pro (adminmenueditor[.]com), pushing malicious plugin updates to customers. The campaign distributed trojanized versions 2.35 and 2.36, affecting at least 230 customers and 1,500 WordPress sites. The developer, Janis Elsts, reported that the attacker likely gained root-level server access to the distribution infrastructure, allowing them to compromise even the remediation version (2.36) shortly after its release.
The attack chain involves the delivery of a malicious PHP file that acts as a web shell and the creation of hidden administrative accounts within the WordPress database. This provides the attacker with persistent, unauthorized access to the victim's WordPress environment. The incident highlights the severe risks of third-party plugin ecosystems, as even premium, widely-used software can be leveraged for mass exploitation.
The business impact is significant for affected organizations, potentially leading to total site takeover, data theft, and further malware distribution. Affected sectors include any organization utilizing WordPress for web presence, with a high volume of installs in the information technology and commercial sectors. Immediate action is required to verify plugin integrity and audit user accounts.
