CyberRota Analysis
AI-GeneratedFluent Forms Pro version 6.2.7 is vulnerable due to an embedded malicious code introduced through a compromised plugin build, allowing attackers to establish a backdoor REST API endpoint and create a passwordless administrator account. This critical vulnerability can lead to unauthorized access and persistent control over affected systems, making it imperative for all users of Fluent Forms Pro to prioritize immediate remediation. Organizations utilizing this plugin should assess their installations and consider updating or removing the affected version to mitigate potential exploitation.
Original NVD Description
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.