Malicious Admin Menu Editor Pro Plugin Backdoors WordPress Sites
Compromised maintainer website distributes malicious updates creating hidden administrator accounts

Key Takeaways
- Threat actor compromised the Admin Menu Editor Pro plugin maintainer's website.
- Malicious plugin updates were distributed to customers, creating hidden administrator accounts.
- Affected sites number over 1,500 WordPress installations.
- The hidden account provides unauthorized administrative access without detection.
- Site owners should verify plugin integrity and remove any suspicious admin accounts.
Related Security News

FBI Warns ShinyHunters Members Following Dutch Police Arrest of Alleged Leader
The FBI has issued warnings to members of the ShinyHunters extortion group, urging them to turn themselves in following the arrest of an alleged leader by Dutch police. The operation marks a coordinated law enforcement effort to disrupt the group's activities.

Dutch Police Confirm Arrest of 24-Year-Old in ShinyHunters Investigation
Dutch authorities have confirmed the arrest of a 24-year-old man from Amsterdam in connection with an investigation targeting the ShinyHunters hacking group. The operation forms part of broader law enforcement efforts to disrupt the threat actor's activities, though specific details regarding the evidence or the suspect's alleged role remain under investigation.



