A security issue has been identified in the Fluent Forms Pro WordPress plugin, linked to a tampered malicious version of the plugin (version 6.2.7) that was distributed via a decommissioned update server operated by the plugin's developer.
This malicious version of the plugin hides extra code that creates a secret backdoor entry point for attackers to access your site, installs hidden administrator accounts that let users log in without any password, saves harmful files in core parts of your site that remain even if you delete the Fluent Forms Pro plugin, and sets up hidden automated tasks that continue running after the plugin is removed.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73532