PHP · AUGUST 2026 · EARLY WARNING

Fluent Forms Pro 6.2.7 Vulnerability: Supply-Chain Attack Alert

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
fluent forms pro (other)
Patched version
Not yet available
CVE-2026-73532

Fluent Forms Pro 6.2.7 reportedly contains a malicious code vulnerability introduced via a tampered plugin build. Users of this version are advised to check for signs of compromise and upgrade as soon as possible.

What happened

Fluent Forms Pro 6.2.7 is under investigation for containing an embedded malicious code vulnerability. This vulnerability was introduced via a tampered plugin build that included a rogue PHP file. This file established a backdoor REST API endpoint, dropped persistent PHP files in the mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that persisted even after plugin removal.

The tampered build was served through a decommissioned update server. The rogue PHP file, libs/class-license-sync.php, was loaded via a require_once directive added to fluentformpro.php. This introduced significant security risks including unauthorized access and persistent backdoors.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If fluent forms pro is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Fluent Forms Pro version 6.2.7, you are potentially affected.

What should I do right now?

Stop using Fluent Forms Pro 6.2.7. Check your systems for signs of compromise and upgrade to a secure version immediately.

Has an official fix been released?

No official fix has been published yet. Monitor the primary sources for updates.

Where can I get more information?

Consult the NVD page for CVE-2026-73532 for the latest details and updates.

Sources

Join the 0Day waitlist →

← Back to all threats