CVE-2026-73532: embedded malicious code in WPManageNinja Fluent Forms Pro

An attacker who distributes a tampered Fluent Forms Pro build can embed persistent backdoor code that compromises sites running the plugin; this issue is tracked as CVE-2026-73532. The build identified in reports affects Fluent Forms Pro version 6.2.7 (branch 6.x) and was introduced via a tampered plugin package served through a decommissioned update server, meaning affected sites received a compromised plugin file rather than a vendor-signed update.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00671
CWE
CWE-506
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: treat sites running Fluent Forms Pro 6.2.7 as potentially compromised because the tampered build included a backdoor and persistent artifacts that survived plugin removal. Immediately isolate affected hosts and follow containment and remediation steps.

What is CVE-2026-73532?

An attacker who distributes a tampered Fluent Forms Pro build can embed persistent backdoor code that compromises sites running the plugin; this issue is tracked as CVE-2026-73532. The build identified in reports affects Fluent Forms Pro version 6.2.7 (branch 6.x) and was introduced via a tampered plugin package served through a decommissioned update server, meaning affected sites received a compromised plugin file rather than a vendor-signed update.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of WPManageNinja Fluent Forms Pro are affected?

BRANCHAFFECTEDFIXED
6.x6.2.7

Is CVE-2026-73532 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-73532

  1. Immediately remove Fluent Forms Pro 6.2.7 and disable the plugin on exposed sites.
  2. Isolate affected systems from the network and restore from a known-clean backup taken before installation of the tampered build.
  3. Search for and remove persistent files (including rogue PHP files in mu-plugins and uploads), scheduled tasks, and any unauthorized administrator accounts; rotate all site and server credentials.
  4. Monitor logs for suspicious REST API activity and follow any vendor guidance or updates when a patched release becomes available.

Frequently asked questions

Is CVE-2026-73532 being actively exploited?

There are no public reports of active exploitation or public exploit code for CVE-2026-73532 as of 2026-09-29.

Which Fluent Forms Pro versions are affected by CVE-2026-73532?

Reports identify Fluent Forms Pro version 6.2.7 (branch 6.x) as affected.

Is there a patch for CVE-2026-73532?

No patched version is listed for this issue as of 2026-09-29; follow vendor guidance and apply mitigations until a fix is published.

What can an attacker do with CVE-2026-73532?

The tampered build introduced a rogue PHP file and backdoor REST endpoint, dropped persistent files, installed a passwordless administrator account, and registered scheduled tasks that could survive plugin removal.

References