Fluent Forms Pro 6.2.7 Vulnerability: Supply-Chain Attack Alert
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- fluent forms pro (other)
- Patched version
- Not yet available
Fluent Forms Pro 6.2.7 reportedly contains a malicious code vulnerability introduced via a tampered plugin build. Users of this version are advised to check for signs of compromise and upgrade as soon as possible.
What happened
Fluent Forms Pro 6.2.7 is under investigation for containing an embedded malicious code vulnerability. This vulnerability was introduced via a tampered plugin build that included a rogue PHP file. This file established a backdoor REST API endpoint, dropped persistent PHP files in the mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that persisted even after plugin removal.
The tampered build was served through a decommissioned update server. The rogue PHP file, libs/class-license-sync.php, was loaded via a require_once directive added to fluentformpro.php. This introduced significant security risks including unauthorized access and persistent backdoors.
What to do about it
- Avoid using Fluent Forms Pro 6.2.7.
- Check your systems for signs of compromise if you are currently using this version.
- Upgrade to a secure version of Fluent Forms Pro as soon as possible.
- Monitor the primary sources for updates on a patched version.
- Consult the NVD page for CVE-2026-73532 for the latest information and updates.
How 0Day would have caught this
fluent forms pro is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Fluent Forms Pro version 6.2.7, you are potentially affected.
What should I do right now?
Stop using Fluent Forms Pro 6.2.7. Check your systems for signs of compromise and upgrade to a secure version immediately.
Has an official fix been released?
No official fix has been published yet. Monitor the primary sources for updates.
Where can I get more information?
Consult the NVD page for CVE-2026-73532 for the latest details and updates.