Impact
Fluent Forms Pro 6.2.7 was shipped with a tampered build that embedded malicious PHP code. The rogue file, loaded by the main plugin file, created a hidden REST API endpoint, dropped persistent PHP files into the mu‑plugins and uploads directories, installed a password‑less administrator account, and registered scheduled tasks that survive plugin removal. This creates a full backdoor that allows an attacker to execute arbitrary code on the host, gain administrative privileges, and maintain persistence.
Affected Systems
The vulnerability affects the WPManageNinja product Fluent Forms Pro, specifically version 6.2.7. No earlier or later versions are mentioned as affected, and the issue originates from a decommissioned update server that served the tampered build.
Risk and Exploitability
With a CVSS score of 9.3, the vulnerability is considered Critical. The EPSS score is not available, so the current exploitation likelihood is unknown, and the vulnerability is not listed in the CISA KEV catalog. The exploitation requires the plugin to be installed; the backdoor is activated through an included PHP file that, when the plugin loads, exposes a REST endpoint and creates a rogue admin user. The attack vector is inferred to be remote via the website’s plugin system, meaning anyone who can trigger the plugin’s loading process can potentially exploit it.
OpenCVE Enrichment