By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Malicious Plugin Backdoors 1,500 WordPress Sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to over 200 customers after a threat actor compromised the plugin's maintainer's website. This compromise allowed the attacker to push updates containing a backdoor that creates a hidden user account with administrator privileges. The compromised plugin has affected approximately 1,500 WordPress websites, according to Wordfence, a cybersecurity firm that discovered the vulnerability. The threat actor gained access to the plugin's official repository by compromising the maintainer's website, which then allowed them to push malicious updates to users who had automatically updated the plugin. The backdoor functionality enables the attacker to log into affected websites without the legitimate administrator's knowledge or consent. This hidden administrator account can be used to perform various malicious activities, including injecting further malware, redirecting traffic, or stealing sensitive data. Wordfence reported that the malicious updates were pushed out on November 29, 2023. The firm's analysis indicates that the backdoor was designed to be stealthy, making it difficult for site owners to detect. The threat actor could potentially add new administrative users, modify existing content, or even execute arbitrary code on the server. The compromise highlights the significant risks associated with software supply chain attacks, where a vulnerability in a trusted software component can lead to widespread compromise. WordPress, being the world's most popular content management system, with an estimated 43% of all websites using it, makes its ecosystem a prime target for attackers. Plugins, which extend WordPress functionality, are particularly vulnerable as they often require extensive permissions and can be complex to secure. The Admin Menu Editor Pro plugin itself is used to customize the WordPress admin menu, a feature that allows users to rearrange, add, or remove items from the dashboard interface. This functionality, while useful for site management, also means the plugin operates with high-level access. Wordfence has provided specific indicators of compromise (IOCs) to help affected users identify the malicious activity on their sites. They are advising users to immediately update to a clean version of the plugin, which is version 2.9.4, and to thoroughly audit their website for any unauthorized changes or added administrator accounts. The incident underscores the critical importance of robust security practices for plugin developers and the need for vigilant monitoring by website administrators. Automatic updates, while convenient for patching known vulnerabilities, can also accelerate the spread of malicious code if the update source is compromised. The number of affected sites, estimated at 1,500, represents a significant portion of the plugin's user base, which is estimated to be over 100,000 active installations. The attackers' ability to leverage a trusted channel for distribution means that even sites that regularly update their software were at risk. This incident is a stark reminder of the ongoing threats to web application security and the need for continuous vigilance.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.