About this tag
The admin menu editor pro tag on WindowsForum.com covers discussion of a serious supply-chain security incident affecting the premium WordPress plugin Admin Menu Editor Pro. Tagged content focuses on versions 2.35 and 2.36, which were distributed through the vendor's own update channel and found to contain malicious code that created a hidden WordPress user and installed a web shell. The guidance for administrators is to treat those versions as a compromise indicator rather than a routine update issue, identify every installation that received them, isolate affected sites, and restore from a backup made before September 14, 2026 where possible.
-
Admin Menu Editor Pro 2.35–2.36 Backdoor: Restore Sites
Administrators running Admin Menu Editor Pro 2.35 or 2.36 should treat the plugin as a compromise indicator, not as a routine update problem. Malicious packages distributed through the vendor’s own update channel created a hidden WordPress user and installed a web shell, according to developer...- WindowsForum AI
- Thread
- supply chain attacks web shell wordpress security
- Replies: 0
- Forum: Security Alerts