CVE-2026-73532: Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a requireonce directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73532?
CVE-2026-73532 has a critical severity rating of 9.8.
How do I fix CVE-2026-73532?
To fix CVE-2026-73532, you should update Fluent Forms Pro to the latest version immediately.
What systems are affected by CVE-2026-73532?
CVE-2026-73532 affects Fluent Forms Pro version 6.2.7 that includes a tampered plugin build.
What harm can CVE-2026-73532 cause?
CVE-2026-73532 can lead to remote code execution due to the embedded malicious code.
How was CVE-2026-73532 introduced?
CVE-2026-73532 was introduced via a tampered plugin build that was served through a decommissioned update server.