Malicious Admin Menu Editor Pro versions compromise 1,500 WordPress sites

0
27
Malicious Admin Menu Editor Pro versions compromise 1,500 WordPress sites Credit: Bleeping Computer
Malicious Admin Menu Editor Pro versions compromise 1,500 WordPress sites Credit: Bleeping Computer

A security incident involving the premium Admin Menu Editor Pro plugin has potentially exposed thousands of WordPress websites after an attacker compromised the plugin developer’s website and distributed malicious updates.

Developer Janis Elsts said an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 of the Pro plugin. The update contained an includes/wp-user-consent.php file that installed a web shell on affected websites and created a hidden user account.

After detecting the intrusion, Elsts removed the malicious update and released a clean version 2.36 at 19:00 UTC on the same day. However, the attacker still had access to the website and also compromised the new version.

Admin Menu Editor Pro is the premium version of Admin Menu Editor, a WordPress plugin used on more than 300,000 websites. It allows administrators to customize Dashboard menus, hide plugins from other users, set role-based access limits and create login or logout redirects.

According to Elsts, version 2.35 was available on the official website from approximately 06:00 to 13:00 UTC. At least 230 customers installed the malicious update across 1,500 websites, although the actual number could be higher because some customers may have downloaded the compromised version 2.36.

“Based on analysis of update server logs, approximately 230 customers were affected in the initial attack. The malicious version was installed at least 1500 sites (often multiple sites per customer),” Elsts told a publication.

“Several hundred additional customers downloaded the plugin in or near the relevant time window, and could have also been affected,” he added.

The investigation suggests the attacker likely obtained root-level access to the server. Elsts therefore took the website offline until it could be restored safely.

Customers who installed versions 2.35 or 2.36 should check for includes/wp-user-consent.php, a new /wp-content/object-cache/ directory, a user beginning with wp_ in the wp_users table and database options named like wp_ocache*.

Version 2.34 is believed to be clean, while the free version of Admin Menu Editor does not appear to be affected.

The recommended fix is to restore affected websites from a safe backup created before September 14. If that is not possible, users should delete the plugin, the /wp-content/object-cache/ directory and the identified database entries.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.