LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

zeroday.news ·

A malicious version of the Admin Menu Editor Pro plugin for WordPress was distributed to over 200 customers, affecting at least 1,500 websites, after an attacker compromised the maintainer's website and pushed updates containing a backdoor. The incident, which began on Monday, September 14, involved the distribution of trojanized versions of the premium plugin.

According to developer Janis Elsts, an unauthorized party gained access to the adminmenueditor.com website and uploaded version 2.35 of the plugin as an update. This version, available from approximately 06:00 to 13:00 UTC on September 14, included a file named `includes/wp-user-consent.php`. This file installed a web shell on affected websites and created a hidden user account in the `wp_users` table, typically prefixed with `wp_`.

After discovering the intrusion, Elsts removed the malicious update and released a clean version 2.36 at 19:00 UTC on the same day. However, the attacker still maintained access to the website and subsequently compromised this new version as well. The developer indicated that the attacker likely achieved root-level server access.

The Admin Menu Editor Pro plugin is the premium counterpart to the free Admin Menu Editor, which is installed on over 300,000 WordPress sites. The plugin allows administrators to customize dashboard menus, manage plugin visibility, set role-based access limits, and configure login/logout redirects. The free version of the plugin is not believed to have been affected.

Based on an analysis of update server logs, approximately 230 customers initially installed the malicious version 2.35, impacting at least 1,500 sites. The developer warned that the total number of affected customers could be higher, as it is difficult to precisely determine how many also installed the compromised version 2.36. Several hundred additional customers downloaded the plugin around the time of the attack and could also be affected.

To protect customers, Elsts took the adminmenueditor.com website offline, replacing it with a static page detailing the incident and providing guidance for affected users. The developer recommends that anyone who installed Admin Menu Editor Pro versions 2.35 or 2.36 check for specific indicators of compromise. These include the presence of `includes/wp-user-consent.php` within the `admin-menu-editor-pro` directory, a new directory named `/wp-content/object-cache/`, and options in the `wp_options` table named similar to `wp_ocache*`.

The most reliable remediation advised is to restore the compromised site from a backup created before September 14. If a backup is unavailable, Elsts recommends deleting the plugin, the `/wp-content/object-cache/` directory, and the malicious database entries. Version 2.34 of the plugin is considered clean. The developer has confirmed that the incident was limited to their infrastructure and has apologized to affected customers.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and