Malicious WordPress Plugin Backdoors 1,500 Business Sites

A malicious WordPress plugin disguised as a legitimate tool has quietly compromised more than 1,500 websites, handing attackers full administrative control without triggering a single alarm. If your business runs on WordPress — and roughly 43% of all websites do — this incident is a direct warning, not background noise.

What Happened With the Malicious WordPress Plugin

The attack centred on a counterfeit version of Admin Menu Editor Pro, a popular plugin that lets site administrators customise their WordPress dashboard. Cybercriminals created a convincing fake of the paid plugin and distributed it through unofficial channels, where budget-conscious users often search for premium tools without paying for them. Once installed, the plugin silently planted a backdoor — a hidden entry point that let attackers return to the site whenever they wanted, even if the plugin was later removed. Over 1,500 sites were confirmed compromised before the campaign was widely identified.

This is not a sophisticated nation-state attack. It is an opportunistic, scalable operation designed to exploit one very common human behaviour: looking for a shortcut. The attackers did not need to break through firewalls or crack passwords. They simply waited for site owners to install their trap.

Why SMBs Are the Real Target Here

Large enterprises typically have dedicated security teams vetting every piece of third-party software before it touches a production environment. Small and medium businesses rarely do. A single employee managing a company WordPress site — handling content, plugins, and updates alongside a dozen other responsibilities — is exactly the kind of target this attack was designed for.

When a backdoor is installed, the attacker's options are wide open. They can steal customer data, inject payment-skimming scripts that silently harvest credit card details, redirect visitors to phishing pages, or simply sell access to your site on dark web forums to the highest bidder. By the time most businesses notice something is wrong, the damage is already done and the credentials, customer records, or payment data have already changed hands underground.

How Stolen Credentials End Up on the Dark Web After an Attack Like This

Here is where the risk compounds. A backdoored WordPress site does not just affect your website. If your site stores customer accounts, employee login details, or integrates with other business tools, those credentials can be harvested and packaged into what the security industry calls infostealer dumps — large files of stolen usernames and passwords traded openly on dark web markets and closed forums.

Breachrr monitors these exact sources continuously. Our systems scan breach databases, infostealer logs, dark web markets, public code repositories, and domain infrastructure to detect when your business data surfaces somewhere it should not be. The challenge for most SMBs is that they have no visibility into this layer of the internet at all. They find out their credentials have been compromised the same way their customers do — when accounts start getting accessed without authorisation.

The Admin Menu Editor Pro incident is a reminder that the attack surface for a small business is broader than most owners realise. Your website, your plugins, your staff email addresses, and your customer database are all potential entry points — and all of them can generate data that flows downstream into underground markets.

What You Should Do Right Now

Start with your WordPress installation. Audit every plugin currently active on your site and verify it was downloaded directly from the official WordPress plugin repository or purchased directly from the developer's own website. If anyone on your team downloaded a premium plugin from a third-party site or a file-sharing platform to avoid the licence fee, treat that plugin as potentially compromised and remove it immediately.

Beyond your website, consider what credentials your business is actually exposing. Employee email addresses used to register for services, passwords reused across platforms, and customer account data held in your database all carry real risk if your site has been touched by a malicious WordPress plugin or any similar supply-chain style attack.

The businesses that come through incidents like this with minimal damage are not necessarily the ones with the biggest security budgets. They are the ones who know what is exposed and act before attackers do. Run a free audit at breachrr.com/audit to find out whether your business data is already circulating in places you have never looked.

Want to see if your company is exposed?

Want to see if your company is exposed?

Run a free audit →