Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-73532: Fluent Forms Pro Malicious Code Injection via Tampered Plugin
CVE-2026-73532 · published 21 days ago
Summary
Fluent Forms Pro plugins may be compromised by malicious code. This can lead to unauthorized access to your website and data. To protect yourself, update to the latest version of Fluent Forms Pro and monitor your website for any suspicious activity.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wpmanageninja | fluent forms pro | 6.2.7 |
Original advisory text
Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-506Embedded Malicious Code
Timeline
Published13 Aug 2026
Updated3 Sep 2026
First seen13 Aug 2026
Monitor software like this
Free during beta