{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fluent-forms-pro-6.2.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-73532"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Fluent Forms Pro (6.2.7)"],"_cs_severities":["critical"],"_cs_tags":["supply-chain","backdoor","wordpress"],"_cs_type":"advisory","_cs_vendors":["Fluent Forms"],"content_html":"\u003cp\u003eFluent Forms Pro version 6.2.7 was subjected to a supply chain attack where a decommissioned update server was leveraged to deliver a compromised plugin build. This tampered build included an embedded malicious PHP file, 'libs/class-license-sync.php', which was dynamically invoked via an added 'require_once' statement in the core 'fluentformpro.php' file. Once active, this backdoor established unauthorized REST API endpoints and implemented multiple persistence mechanisms. The compromise allows attackers to maintain access even if the parent plugin is removed. This incident highlights the critical risk of relying on legacy update infrastructure and the importance of verifying plugin integrity from authorized sources. Defenders should immediately audit WordPress environments for the presence of the malicious file and unauthorized administrator accounts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker redirects traffic from a decommissioned update server to serve a tampered plugin archive.\u003c/li\u003e\n\u003cli\u003eAdministrator or automated system updates Fluent Forms Pro to the malicious version 6.2.7.\u003c/li\u003e\n\u003cli\u003eThe modified 'fluentformpro.php' triggers 'require_once' to load the malicious 'libs/class-license-sync.php'.\u003c/li\u003e\n\u003cli\u003eThe backdoor script registers an unauthorized REST API endpoint for remote command execution.\u003c/li\u003e\n\u003cli\u003eThe script drops persistent files within the 'mu-plugins' directory to ensure continued execution across requests.\u003c/li\u003e\n\u003cli\u003eThe backdoor creates a passwordless administrative account to secure ongoing unauthorized access.\u003c/li\u003e\n\u003cli\u003eScheduled tasks (WP-Cron) are registered to maintain command and control callbacks.\u003c/li\u003e\n\u003cli\u003eFinal objective achieved: long-term persistence and full administrative control of the WordPress instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe compromise of Fluent Forms Pro 6.2.7 enables complete site takeover, unauthorized exfiltration of form-submitted data, and potential lateral movement from the affected web server. Given the high privileges associated with the injected administrator account and the persistence in 'mu-plugins', attackers can maintain access indefinitely regardless of plugin status. All organizations using this version should consider their form data and administrative credentials compromised.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and remove the file 'libs/class-license-sync.php' from all WordPress installations.\u003c/li\u003e\n\u003cli\u003eAudit the 'wp-content/mu-plugins' directory for any unauthorized or unknown PHP files.\u003c/li\u003e\n\u003cli\u003eReview the WordPress user database for unauthorized accounts, specifically those without passwords or with anomalous creation dates.\u003c/li\u003e\n\u003cli\u003eRemove any unauthorized WP-Cron tasks associated with the identified backdoor or plugin directories.\u003c/li\u003e\n\u003cli\u003eImmediately upgrade to a verified, clean version of the plugin obtained directly from the official vendor repository.\u003c/li\u003e\n\u003cli\u003eRestrict outbound network access from web servers to block unauthorized C2 communication paths identified in server access logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:47:18Z","date_published":"2026-08-13T16:47:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-fluent-forms-backdoor/","summary":"Fluent Forms Pro 6.2.7 was compromised through a supply chain attack involving a decommissioned update server that served a tampered plugin build, leading to unauthorized backdoor access, persistence, and privilege escalation.","title":"Supply Chain Compromise of Fluent Forms Pro via Tampered Update Server","url":"https://feed.craftedsignal.io/briefs/2026-08-fluent-forms-backdoor/"}],"language":"en","title":"CraftedSignal Threat Feed - Fluent Forms Pro (6.2.7)","version":"https://jsonfeed.org/version/1.1"}