CVE-2026-73532 (matched: php)

  • Thursday, 13th August, 2026
  • 22:04pm

A compromised version of the popular WordPress form plugin Fluent Forms Pro, specifically version 6.2.7, contains hidden harmful code that was added to a tampered build of the plugin distributed through a decommissioned official update server. The hidden code creates a secret backdoor that lets attackers access your site, drops persistent hidden files in your site’s core plugin and media upload folders that remain even if you delete the Fluent Forms Pro plugin, adds a new administrator account that requires no password to log in, and sets up automated tasks that continue running even after the plugin is removed. If your website is running this specific version of Fluent Forms Pro, attackers could use this vulnerability to take full control of your site, steal visitor or business data, use your site to send spam or host harmful content, or lock you out of your own website entirely.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73532

« Back