
On Monday, an attacker who had obtained root-level access to adminmenueditor.com — the distribution server for the popular Admin Menu Editor Pro WordPress plugin — pushed a malicious update under version 2.35. The tampered update contained a hidden file (includes/wp-user-consent.php) that functioned as a web shell, giving the attacker persistent remote access to any WordPress site where the update was installed.
The malicious version was pushed to over 200 direct paying customers of the Pro plugin. Because some customers manage multiple sites, the total number of affected WordPress installations reached approximately 1,500. Developer Janis Elsts discovered the breach and immediately took the adminmenueditor.com website offline to prevent further distribution. Elsts noted that the attacker’s root-level server access suggests the compromise went beyond the plugin’s own codebase — the hosting environment itself was breached. The site is being restored from a clean state before going back online.
How to check if you’re affected
Affected versions of Admin Menu Editor Pro are exactly version 2.35 of the plugin. If you have installed or received an automatic update to this version, open your site’s wp-content/plugins/admin-menu-editor-pro/includes/ directory and look for a file named wp-user-consent.php — its presence confirms a compromised install. Remove the plugin entirely, rotate all WordPress admin credentials, and audit your server for any additional web shells or backdoor accounts.
