{"cve":"CVE-2026-73532","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"unaffected","versions":null}],"enrichment":{"confidence":80.0,"confidence_source":"inferred","scores":[{"score":80.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"product":"wordpress","vendor":"wordpress"},{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"6.2.7"}}],"enrichment":{"confidence":93.0,"confidence_source":"matching","scores":[{"score":93.0,"source":"matching"}]},"original":{"product":"Fluent Forms Pro","source":"cna","vendor":"WPManageNinja"},"product":"fluent_forms","vendor":"wpmanageninja"}],"created":"2026-08-13T17:45:03.677444+00:00","updated":"2026-08-14T10:00:03.919570+00:00","vendors":["wordpress","wordpress$PRODUCT$wordpress","wpmanageninja","wpmanageninja$PRODUCT$fluent_forms"]},"epss":{"score":0.00671},"mitre":{"cpes":[],"created":"2026-08-13T16:01:19.629000+00:00","description":"Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2026/73xxx/CVE-2026-73532.json","references":["https://patchstack.com/database/wordpress/plugin/fluentformpro/vulnerability/wordpress-fluent-forms-pro-add-on-pack-plugin-6-2-7-6-2-7-remote-code-execution-vulnerability","https://wordpress.org/plugins/fluentform/","https://wpmanageninja.com/security-incident-on-31-july-2026/","https://www.vulncheck.com/advisories/fluent-forms-pro-embedded-malicious-code-via-tampered-plugin-build"],"title":"Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build","updated":"2026-08-14T16:48:08.232000+00:00","vendors":[],"weaknesses":["CWE-506"]},"nvd":{"cpes":[],"created":"2026-08-13T16:19:05.480000+00:00","description":"Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-73532.json","references":["https://patchstack.com/database/wordpress/plugin/fluentformpro/vulnerability/wordpress-fluent-forms-pro-add-on-pack-plugin-6-2-7-6-2-7-remote-code-execution-vulnerability","https://wordpress.org/plugins/fluentform/","https://wpmanageninja.com/security-incident-on-31-july-2026/","https://www.vulncheck.com/advisories/fluent-forms-pro-embedded-malicious-code-via-tampered-plugin-build"],"title":null,"updated":"2026-09-09T20:35:08.537000+00:00","vendors":[],"weaknesses":["CWE-506"]},"opencve":{"changes":[{"created":"2026-08-13T16:15:00+00:00","data":[{"details":{"new":"Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.","old":null},"type":"description"},{"details":{"new":"Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build","old":null},"type":"title"},{"details":{"added":["CWE-506"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://patchstack.com/database/wordpress/plugin/fluentformpro/vulnerability/wordpress-fluent-forms-pro-add-on-pack-plugin-6-2-7-6-2-7-remote-code-execution-vulnerability","https://wordpress.org/plugins/fluentform/","https://wpmanageninja.com/security-incident-on-31-july-2026/","https://www.vulncheck.com/advisories/fluent-forms-pro-embedded-malicious-code-via-tampered-plugin-build"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"8185190e-e1f9-4003-90cd-4270dd41799b"},{"created":"2026-08-14T10:15:00+00:00","data":[{"details":["wordpress","wordpress$PRODUCT$wordpress","wpmanageninja","wpmanageninja$PRODUCT$fluent_forms"],"type":"first_time"},{"details":{"added":["wordpress","wordpress$PRODUCT$wordpress","wpmanageninja","wpmanageninja$PRODUCT$fluent_forms"],"removed":[]},"type":"vendors"}],"id":"3ee30f2b-7eff-4b81-9918-f1d63d54ad0b"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-08-13T16:01:19.629000+00:00","provider":"mitre"},"description":{"data":"Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{"score":0.00671},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://patchstack.com/database/wordpress/plugin/fluentformpro/vulnerability/wordpress-fluent-forms-pro-add-on-pack-plugin-6-2-7-6-2-7-remote-code-execution-vulnerability","https://wordpress.org/plugins/fluentform/","https://wpmanageninja.com/security-incident-on-31-july-2026/","https://www.vulncheck.com/advisories/fluent-forms-pro-embedded-malicious-code-via-tampered-plugin-build"],"providers":["mitre","nvd"]},"title":{"data":"Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build","provider":"mitre"},"updated":{"data":"2026-08-14T10:00:03.919570+00:00","provider":"enrichment"},"vendors":{"data":["wordpress","wordpress$PRODUCT$wordpress","wpmanageninja","wpmanageninja$PRODUCT$fluent_forms"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-506"],"providers":["mitre","nvd"]}}}