# Trojanized WordPress plugin update reaches at least 1,500 sites

_Published Tuesday, September 15, 2026 at 5:07 PM EDT · Security · Latest · Tier 2 — Notable_

![Trojanized WordPress plugin update reaches at least 1,500 sites — Primary](https://www.bleepstatic.com/content/hl-images/2026/06/18/WordPress.jpg)

Malicious updates for the premium Admin Menu Editor Pro WordPress plugin were installed on at least 1,500 sites, according to the plugin's developer. The compromised versions 2.35 and 2.36 created a hidden user account and included code that installed a web shell. The developer took the distribution site offline after determining the attacker may have had root-level server access. The free version was not reported affected.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/)

---
Canonical: https://techandbusiness.org/newswire/JRijXwbnkTCxiqRikMANJt
Published: 2026-09-15T21:07:30.591Z
Story chronology: 2026-09-15T20:34:15.000Z
Retrieved: 2026-09-15T23:11:56.328Z
Publisher: Tech & Business (techandbusiness.org)
