Admin Menu Editor Pro update server hacked, plugin backdoored on 1,500 WordPress sites
A threat actor breached the website of Admin Menu Editor Pro maintainer Janis Elsts and pushed a malicious version 2.35 update that installed a web shell and created a hidden admin account on customer sites. Even after Elsts released a clean version 2.36, the attacker retained access and compromised that release too, affecting an estimated 230 customers and at least 1,500 sites.