Admin Menu Editor Pro Supply Chain Attack
Score: 7/10

Admin Menu Editor Pro Supply Chain Attack

A supply chain attack against Admin Menu Editor Pro compromised at least 1,500 WordPress sites via trojanized plugin updates that install web shells and hidden accounts.

Executive Summary

In September 2026, an unidentified threat actor compromised the official website of Admin Menu Editor Pro (adminmenueditor[.]com), pushing malicious plugin updates to customers. The campaign distributed trojanized versions 2.35 and 2.36, affecting at least 230 customers and 1,500 WordPress sites. The developer, Janis Elsts, reported that the attacker likely gained root-level server access to the distribution infrastructure, allowing them to compromise even the remediation version (2.36) shortly after its release.

The attack chain involves the delivery of a malicious PHP file that acts as a web shell and the creation of hidden administrative accounts within the WordPress database. This provides the attacker with persistent, unauthorized access to the victim's WordPress environment. The incident highlights the severe risks of third-party plugin ecosystems, as even premium, widely-used software can be leveraged for mass exploitation.

The business impact is significant for affected organizations, potentially leading to total site takeover, data theft, and further malware distribution. Affected sectors include any organization utilizing WordPress for web presence, with a high volume of installs in the information technology and commercial sectors. Immediate action is required to verify plugin integrity and audit user accounts.

Key Details

Threat Name

Admin Menu Editor Pro Supply Chain Attack

Affects

—

Adversary

—

Malware/Tools

Admin Menu Editor Pro, Cerber, EtherHiding

Report Score

7out of 10
Quality Score
Good
IOC Quality6
TTP Details7
Detection Guidance5
Enterprise Relevance7
Clarity & Structure8
Technical Depth6

Sources