A security flaw has been identified in version 6.2.7 of Fluent Forms Pro, a popular WordPress plugin used to add contact forms, surveys and other input fields to websites. This flaw comes from a tampered, malicious version of the plugin that was accidentally distributed to users via an old, no-longer-active update server.
The malicious version of the plugin includes hidden harmful code that gives attackers full, unauthorized control of any website running the affected build. This code creates a secret, hidden entry point that lets attackers access and take over the site, plants hidden files that remain on the server even if you delete the Fluent Forms Pro plugin, creates a secret site administrator account with no password that lets anyone log into your website’s backend without permission, and sets up hidden background tasks that continue running even after the plugin is removed.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-73532