Skip to main content
CyberSingle-sourceMediumDeveloping
4.9

Supply-chain attack: backdoored Admin Menu Editor Pro hits 1,500 WordPress sites

A threat actor compromised the Admin Menu Editor Pro plugin's distribution channel, pushing malicious updates to over 200 customers that created hidden admin accounts, affecting an estimated 1,500 WordPress sites. The attack is a supply-chain compromise of a trusted software update mechanism, with the full scope and persistence still under investigation. This highlights the risk of third-party plugin ecosystems and the need for immediate credential rotation and site audits.

BleepingComputerabout 11 hours agoengCredibility 32%View source

Score Breakdown

Mosaic Score4.9
Confidence0.5
Significance0.5
Source credibility0.3
Source

Related signals

8 found