CVE-2026-73532

9.8

WPManageNinja · Fluent Forms Pro

Fluent Forms Pro version 6.2.7 contained a malicious backdoor injected via a tampered plugin build, allowing unauthorized administrative access and persistent system compromise.

Executive summary

A critical supply chain compromise in WPManageNinja Fluent Forms Pro version 6.2.7 has introduced a backdoor allowing remote code execution and unauthorized administrative access.

Vulnerability

This is an embedded malicious code vulnerability where a tampered plugin build was distributed. The malicious code establishes a backdoor REST API endpoint, creates a passwordless administrator account, and installs persistent PHP files in the server environment.

Business impact

The presence of a backdoor provides attackers with persistent, high-level access to the WordPress environment. This risk includes unauthorized data exfiltration, total site takeover, and the potential for the server to be used as a staging point for broader attacks. With a CVSS score of 9.8, this compromise represents a catastrophic failure of the software supply chain.

Remediation

Immediate Action: Update the plugin to the latest version immediately, and perform a comprehensive security audit of the WordPress installation to identify and remove any unauthorized administrator accounts or persistent malicious files.

Proactive Monitoring: Monitor the WordPress user database for unauthorized administrator accounts and check the mu-plugins and uploads directories for suspicious PHP files that may have been dropped by the backdoor.

Compensating Controls: Ensure the site is behind a robust WAF and restrict access to the REST API endpoints if they are not strictly required for site functionality.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This is an extremely severe incident requiring immediate attention. Organizations using version 6.2.7 of Fluent Forms Pro must not only update the plugin but also verify the integrity of the entire WordPress instance, as the backdoor is designed to maintain persistence even after the plugin is removed.

More WPManageNinja CVEs