Trusted WordPress update backdoors at least 1,500 customer sites
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 16th, 2026.
A trusted update channel delivered malicious code to at least one thousand five hundred WordPress sites. An attacker compromised the Admin Menu Editor Pro maintainer’s website and inserted a web shell and hidden user account into versions 2.35 and 2.36. The developer estimated that at least 230 customers installed the first malicious update, often across multiple sites, and warned that the total number could be higher. The website was taken offline while the incident was investigated.
Sites that installed the poisoned versions may remain accessible to the attacker even after the plugin itself is removed. Leaders should include smaller software suppliers and their update infrastructure in supply-chain risk planning. Defenders need to identify affected versions, search for hidden accounts and malicious files, and preserve evidence before beginning restoration. The free plugin appears to be unaffected, while version 2.34 is believed to be clean. The safest recovery step is to restore affected sites from a verified backup created before September 14th and then rotate all relevant credentials.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.