Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Summary

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to over 200 customers. A threat actor compromised the plugin's maintainer's website and pushed updates that installed a hidden administrative user account on compromised sites.

IFF Assessment

FOE

The compromise of a popular WordPress plugin to backdoor websites represents a direct threat to defenders' systems and data.

Defender Context

This incident highlights the critical importance of supply chain security for WordPress plugins. Defenders should maintain strict vigilance over the plugins they use, monitor for unexpected user creations or modifications, and ensure plugins are sourced directly from official repositories and kept up-to-date with verified patches.

Read Full Story →