DIRAS TAKE
Urgent: treat sites running Fluent Forms Pro 6.2.7 as potentially compromised because the tampered build included a backdoor and persistent artifacts that survived plugin removal. Immediately isolate affected hosts and follow containment and remediation steps.
What is CVE-2026-73532?
An attacker who distributes a tampered Fluent Forms Pro build can embed persistent backdoor code that compromises sites running the plugin; this issue is tracked as CVE-2026-73532. The build identified in reports affects Fluent Forms Pro version 6.2.7 (branch 6.x) and was introduced via a tampered plugin package served through a decommissioned update server, meaning affected sites received a compromised plugin file rather than a vendor-signed update.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of WPManageNinja Fluent Forms Pro are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 6.x | 6.2.7 |
Is CVE-2026-73532 being exploited?
There are no public reports of exploitation or public exploit code as of 2026-09-29.
How to fix CVE-2026-73532
- Immediately remove Fluent Forms Pro 6.2.7 and disable the plugin on exposed sites.
- Isolate affected systems from the network and restore from a known-clean backup taken before installation of the tampered build.
- Search for and remove persistent files (including rogue PHP files in mu-plugins and uploads), scheduled tasks, and any unauthorized administrator accounts; rotate all site and server credentials.
- Monitor logs for suspicious REST API activity and follow any vendor guidance or updates when a patched release becomes available.
Frequently asked questions
Is CVE-2026-73532 being actively exploited?
There are no public reports of active exploitation or public exploit code for CVE-2026-73532 as of 2026-09-29.
Which Fluent Forms Pro versions are affected by CVE-2026-73532?
Reports identify Fluent Forms Pro version 6.2.7 (branch 6.x) as affected.
Is there a patch for CVE-2026-73532?
No patched version is listed for this issue as of 2026-09-29; follow vendor guidance and apply mitigations until a fix is published.
What can an attacker do with CVE-2026-73532?
The tampered build introduced a rogue PHP file and backdoor REST endpoint, dropped persistent files, installed a passwordless administrator account, and registered scheduled tasks that could survive plugin removal.
References
- nvd.nist.gov/vuln/detail/CVE-2026-73532
- cve.org/CVERecord?id=CVE-2026-73532
- wpmanageninja.com/security-incident-on-31-july-2026
- wordpress.org/plugins/fluentform
- patchstack.com/database/wordpress/plugin/fluentformpro/vulnerability/wordpress-fluent-forms-pro-add-on-pack-plugin-6-2-7-6-2-7-remote-code-execution-vulnerability
- vulncheck.com/advisories/fluent-forms-pro-embedded-malicious-code-via-tampered-plugin-build
- All WPManageNinja CVEs on CVE Radar
- CVEs published in September 2026