CVE-2026-73532
Received Received - Intake

Fluent Forms Pro 6.2.7 Backdoor via Malicious Plugin Build

Vulnerability report for CVE-2026-73532, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: VulnCheck

Description

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpmanageninja fluent_forms_pro to 6.2.7 (inc)
wpmanageninja ninja_tables_pro to 5.2.11 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-506 The product contains code that appears to be malicious in nature.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a tampered version of Fluent Forms Pro 6.2.7 distributed through a decommissioned update server. The malicious build included a rogue PHP file that created a backdoor REST API endpoint, installed a passwordless admin account, and added persistent PHP files in directories like mu-plugins and uploads. Even after plugin removal, the backdoor and scheduled tasks remained active.

Detection Guidance

Check for the presence of the malicious PHP file libs/class-license-sync.php in the Fluent Forms Pro plugin directory. Look for a require_once directive in fluentformpro.php loading this file. Inspect the mu-plugins and uploads directories for unexpected PHP files. Check for a passwordless administrator account in WordPress user settings and review scheduled tasks for unauthorized entries.

Impact Analysis

Attackers could exploit this backdoor to gain unauthorized access to your website, install malware, inject unwanted ads, or perform other malicious activities. The vulnerability allows persistent access even after removing the plugin, as malicious files and scheduled tasks remain. Users who updated during the five-hour window (July 31, 2026, 14:00–19:00 UTC) are at risk.

Compliance Impact

This vulnerability could lead to unauthorized access, data exfiltration, or persistent backdoors, which may violate GDPR's data protection requirements (e.g., Articles 32, 33) and HIPAA's security rules (e.g., 45 CFR 164.308, 164.312). Unauthorized administrator accounts and persistent PHP files could result in unauthorized processing or disclosure of personal data, triggering breach notification obligations under these regulations.

Mitigation Strategies

Immediately update Fluent Forms Pro to version 6.2.8 or later. Remove the affected plugin if already installed. Delete any suspicious PHP files in mu-plugins and uploads directories. Check WordPress for unauthorized administrator accounts and remove them. Review and clean up any unauthorized scheduled tasks or database entries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73532. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart