Description
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Published: 2026-08-13
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Fluent Forms Pro 6.2.7 was shipped with a tampered build that embedded malicious PHP code. The rogue file, loaded by the main plugin file, created a hidden REST API endpoint, dropped persistent PHP files into the mu‑plugins and uploads directories, installed a password‑less administrator account, and registered scheduled tasks that survive plugin removal. This creates a full backdoor that allows an attacker to execute arbitrary code on the host, gain administrative privileges, and maintain persistence.

Affected Systems

The vulnerability affects the WPManageNinja product Fluent Forms Pro, specifically version 6.2.7. No earlier or later versions are mentioned as affected, and the issue originates from a decommissioned update server that served the tampered build.

Risk and Exploitability

With a CVSS score of 9.3, the vulnerability is considered Critical. The EPSS score is not available, so the current exploitation likelihood is unknown, and the vulnerability is not listed in the CISA KEV catalog. The exploitation requires the plugin to be installed; the backdoor is activated through an included PHP file that, when the plugin loads, exposes a REST endpoint and creates a rogue admin user. The attack vector is inferred to be remote via the website’s plugin system, meaning anyone who can trigger the plugin’s loading process can potentially exploit it.

Generated by OpenCVE AI on August 13, 2026 at 17:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest stable version of Fluent Forms Pro (v6.2.8 or later) from the official WordPress repository or the vendor’s site, replacing the compromised build.
  • Completely uninstall the current plugin from the website, including the main plugin folder, any mu‑plugin files, and uploaded PHP files dropped by the backdoor. Remove the rogue permanent administrator account and delete any related scheduled tasks.
  • Run a comprehensive malware scan of the site to verify that the malicious file libs/class-license-sync.php and other unauthorized PHP files have been removed, ensuring no residual backdoor functionality remains.

Generated by OpenCVE AI on August 13, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Title Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
Weaknesses CWE-506
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-13T16:01:19.629Z

Reserved: 2026-08-12T19:29:19.866Z

Link: CVE-2026-73532

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T16:19:05.480

Modified: 2026-08-13T16:19:05.480

Link: CVE-2026-73532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:45:03Z

Weaknesses