Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

WordPress plugin backdoor security advisory graphic — All IT Services

WordPress Plugin Backdoor Hits 1,500+ Sites: How to Check Yours

A supply-chain attack on a popular WordPress plugin has quietly backdoored more than 1,500 small business websites, and most of the owners have no idea yet.

Attackers compromised the website of Admin Menu Editor Pro, a widely used premium WordPress plugin, and pushed malicious updates out to paying customers. As BleepingComputer reported, the tampered versions planted a hidden web shell and a concealed administrator account on more than 1,500 sites across 230-plus customers, giving attackers a quiet way back in even after the plugin itself is removed.

This slips past most small businesses because the update came from a source they already trust, so there's no dodgy link to spot. If your site runs Admin Menu Editor Pro, check your users list for accounts you don't recognise (especially ones starting with "wp_"), and look in the plugin folder for a file called wp-user-consent.php. Found either? Restore from a clean backup and reset every password tied to that site, don't just delete the plugin and move on. We manage websites for clients across Sydney, the Northern Beaches, Central West NSW and Brisbane, and the pattern we see constantly is that most owners can't tell you which premium plugins are even running on their site, let alone who maintains them. That blind spot is exactly what this attack exploited.

Written by Michael Sacco, Head of Service Delivery, All IT Services. All IT is a Sydney-based managed IT provider supporting hospitality, not-for-profit and wealth management businesses across Australia.


Frequently Asked Questions

Check your WordPress admin under Plugins for "Admin Menu Editor Pro". If someone else manages your site, ask them, or ask us to check for you.
Don't just delete it. Restore from a backup made before the compromise, then remove the account and reset every password tied to that site.
No. Only the paid Pro versions distributed during the compromise were affected; the free version wasn't touched.
Not reliably. It arrived disguised as a legitimate update, so scanners won't flag it unless they check for the specific files and accounts it creates.

Not sure what's running on your website?

We can check your site for this and other silent backdoors, and manage your plugin updates so you're not relying on guesswork.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →