Security Incident Affecting Customers 2026-09-14
If you installed Admin Menu Editor Pro version 2.35, treat the site as compromised. If you installed version 2.36, treat the site as potentially compromised. See what to do below.
Summary
On September 14, 2026, I discovered that a malicious version of admin-menu-editor-pro.zip had been
uploaded to adminmenueditor.com as a new version of the Admin Menu Editor Pro plugin. This showed up as a
version 2.35 update to users who had the plugin active. This version included a new
file includes/wp-user-consent.php that installs a web shell on the user's site.
I removed the malicious update and attempted to resolve the intrusion. A clean version 2.36 was released the same day. However, later on September 14, version 2.36 was also compromised. Investigation of the second intrusion showed that the attacker may have obtained root-level access to the server.
How to check if you're affected
You're affected if you installed version 2.35 of Admin Menu Editor Pro on September 14, 2026. If you installed version 2.36, you may also be affected, particularly if you downloaded it after 19:00 UTC. See the additional check below. Version 2.34 should be clean.
Additionally, you can check for the presence of the web shell and other malicious activity. Things to check for (based on user reports):
- A new
/wp-content/object-cachedirectory that contains a subdirectory with the web shell PHP script. The subdirectory and script will likely have names composed of hex characters. - New option(s) in the
wp_optionstable with a name that starts withwp_ocacheor_wp_ocache_. - A new user whose login is
wp_followed by hex characters. The user likely won't appear in the admin dashboard, but should show up if you directly query thewp_userstable. - MU-plugins (in
/wp-content/mu-plugins) namedwp-followed by hex characters. - A WP-Cron event name
_wp_cconsent_tick. - Potentially also:
- Plugin named
wordpress-cache-optimizer. - User named
wpsecuresuppbot.
- Plugin named
Recommendations for affected users
Because the payload is a web shell, you should assume the attacker had full control of the site. If possible, restore the affected site from a backup made before September 14.
Alternatives
I don't currently have a full understanding of the malicious payload, so the rest of these recommendations may be insufficient.
- If you have version 2.35 of Admin Menu Editor Pro installed, delete it immediately. Some version 2.36 downloads were also compromised, so if you have that version installed, it's recommended to delete it as well.
- Delete the
/wp-content/object-cachedirectory. The/wp-contentdirectory may also contain a file namedobject-cache.php. Some caching plugins create this file for legitimate reasons. If you're using a caching plugin, don't delete this file unless you know what you're doing. - Check the
wp_userstable and delete the hiddenwp_…user if present. Remove thewp_ocache.../_wp_ocache_...options, the_wp_cconsent_tickevent, and any hex-named MU-plugins described above. - Change the passwords of all WordPress users, regenerate the security keys and salts in
wp-config.php, and rotate other credentials stored on the site (database, FTP/SFTP, hosting panel, API keys for third-party services). - Run a full malware scan and review files modified since September 14.
Status Updates
This page will be updated with additional information if/when it becomes available.
Update 2026-10-03 10:20 UTC
Starting incremental rollout of version 2.37.1. This version adds optional checksum and signature verification for plugin updates. It's optional for now because it hasn't been tested on a wide variety of hosting environments yet. If you like, you can change it to "Required" in the "Settings" tab, under "Update verification".
The update also adds a new "Block URLs" feature to the "Tweaks" tab. This is not related to the incident; it's just a new feature I had already been working on.
Update 2026-09-30 10:00 UTC
Starting incremental rollout of version 2.37. This is basically version 2.34 with a new version number, so if you already have 2.37, you don't need to install 2.37. It's the same version that has been available as a temporary download since September 19.
If this goes well, the next version (2.37.1) will be released a few days later. It will include a new security feature for plugin updates, as well as some other minor improvements.
Update 2026-09-28 15:57 UTC
Deployed the new licensing API implementation. License activation and verification should now be working again. In most cases, you shouldn't need to do anything on sites where you've already activated a license in the past. A small fraction of users will need to re-enter their key on sites where a license was activated on September 13 or later.
Since renewals are currently not possible, I've extended access to updates by 2 months for all licenses that had access to updates on September 1 or after. This means you should be able to download the plugin even if your license would originally have expired in September or October.
The new implementation could have bugs. Please report any issues you encounter to one of my emails. Include your license key and any relevant information, like the site URL and the error message, if any.
Update 2026-09-28 14:30 UTC
Deploying the new update server. It's currently serving the old version 2.34, so you shouldn't see any updates yet (unless you're using an even older version). Version 2.37 will be published later.
This means that existing plugin download links should also be working again, and they will also download version 2.34 for now.
I will now start setting up the new licensing API implementation, which should not take more than an hour or two.
Update 2026-09-27
The rebuilt update server and licensing API are approaching a usable state. Hopefully, updates and license activation will be working again in a few days (but not today).
Update 2026-09-20
Working on rebuilding the update server and licensing API nearly from scratch. This could easily take a couple of weeks.
Update 2026-09-19 15:40 UTC
Temporary downloads for version 2.37 are now available. This is intended for existing customers who don't have a clean copy of the plugin. If you already have version 2.34, you don't need to download 2.37. It doesn't contain any new features or fixes; it's basically 2.34 with a different version number.
Update 2026-09-18 14:33 UTC
A customer reports that they saw a user named wpsecuresuppbot and a plugin named
wordpress-cache-optimizer on one of their affected sites. It appears that
wordpress-cache-optimizer is a pre-existing malware plugin that was already
seen at least as far back as July 2026, when it was linked to
other
compromised plugins.
I can only speculate if this is a coincidence or not. The other user reports I've received
so far didn't mention seeing wordpress-cache-optimizer.
Update 2026-09-17 10:41 UTC
A potential vector for root-level privilege escalation has been identified. It's related to a vulnerability in an outdated Linux kernel version.
The earliest sign of compromise I've seen so far is from September 13 at ~19:40 UTC.
Update 2026-09-16 16:29 UTC
Multiple users have asked for clean download links. Unfortunately, I don't yet have a safe way to provide downloads to all customers. If you have an old copy of version 2.34 or even 2.33/2.32, that's likely the best option.
Update 2026-09-15 21:34 UTC
A user has reported additional details about signs of compromise on their site, such as
options named _wp_ocache_ (instead of wp_ocache) and a WP-Cron event
named _wp_cconsent_tick. I've added these to the relevant section above.
Update 2026-09-15 21:03 UTC
Finished sending email notices to affected customers.
Again, even if you haven't received an email from me, that does not necessarily mean you were not affected. My current list of affected customers is likely to be incomplete. Checking your site for malicious files and activity is still recommended.
Update 2026-09-15 19:21 UTC
Started sending security incident notices to affected customers. Look for an email from
whiteshadow@w-shadow.com.
This will mainly cover customers that were affected during the initial compromise. Unfortunately, I don't yet have a reliable way to identify customers affected by the second stage of the attack. Shortly before taking the site offline, I saw evidence suggesting that the attacker may have tried to delete the relevant logs.
Even if you don't receive an email from me, you should not assume that you were not affected. As mentioned above, I don't currently have a comprehensive list of all affected customers. And, of course, automated emails can end up in spam, or the email address I have on file may be out of date.
Update 2026-09-15 14:44 UTC
I'm working on a static site (i.e. this one) to publish these updates.
Update 2026-09-14 ~21:40 UTC
Attempts to stop the intrusion are ineffective. Further investigation indicates the attacker could have root-level access to the server. I've decided to take the server offline. I'm notifying the hosting provider.
This update was added after the fact. The timestamp may be inaccurate.
Update 2026-09-14 ~19:35 UTC
A repeat intrusion was detected.
This update was added after the fact. The timestamp may be inaccurate.
Update 2026-09-14 18:00 UTC
After further analysis, ~300 additional potentially affected customers have been identified. This is based on downloads in or near the relevant time window, not specific version numbers, so it's less reliable.
Update 2026-09-14 16:37 UTC
The current estimate is that about 230 customers were affected [in the initial compromise], often with multiple sites per customer.