Embedded Code Vulnerability in Fluent Forms Pro by WPManageNinja
CVE-2026-73532
9.3CRITICAL
What is CVE-2026-73532?
Fluent Forms Pro version 6.2.7 is impacted by an embedded malicious code vulnerability due to a tampered plugin build deployed via an outdated update server. This manipulation introduced a rogue PHP file, which, when executed, created an insecure REST API endpoint and dropped persistent PHP files within the mu-plugins and uploads directories. Additionally, it installed a passwordless admin account and scheduled tasks that remained active after the removal of the plugin, posing significant risks to site integrity and security.
Affected Version(s)
Fluent Forms Pro 6.2.7
