Find notable cyber news and cases, enriched with sources, timelines, and signals.

Adminmenueditor.com hit by network compromise

Incident
First reported
Last updated
Happening score
H score 45
1 unique sources, 1 articles

Summary

Hide ▲

The adminmenueditor.com website compromise led to malicious Admin Menu Editor Pro updates that installed a web shell and hidden accounts on customer sites, affecting at least 1,500 WordPress sites. The tainted version 2.35 was available for roughly 06:00-13:00 UTC on Monday, and a clean 2.36 was pushed later the same day. The incident put customers at risk of unauthorized access and required site owners to verify whether they had installed the malicious releases.

Timeline

  1. 15.09.2026 23:34 2 articles · 2h ago

    Adminmenueditor.com hit by network compromise

    Initial Disclosure

    The first phase was a maintainer website compromise that seeded malicious Admin Menu Editor Pro version 2.35 to customer sites during a short Monday window. That release planted a hidden account and a web shell before the malicious package was removed.

    Show sources