AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73532

CRITICAL · CVSS 9.8 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Fluent Forms Pro version 6.2.7 is vulnerable due to an embedded malicious code introduced through a compromised plugin build, allowing attackers to establish a backdoor REST API endpoint and create a passwordless administrator account. This critical vulnerability can lead to unauthorized access and persistent control over affected systems, making it imperative for all users of Fluent Forms Pro to prioritize immediate remediation. Organizations utilizing this plugin should assess their installations and consider updating or removing the affected version to mitigate potential exploitation.

CVE
CVE-2026-73532
Severity
CRITICAL
CVSS
9.8
EPSS
0.46%

Original NVD Description

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.