Fluent Forms Pro 6.2.7 存在一个嵌入式恶意代码漏洞,该漏洞源于通过已停用的更新服务器提供的被篡改的插件版本。此篡改版本引入了一个非法的 PHP 文件(libs/class-license-sync.php),该文件通过添加到 fluentformpro.php 中的 require_once 指令加载,从而建立了一个后门 REST API 端点,在 mu-plugins 和 uploads 目录中持久化部署 PHP 文件,创建了一个无需密码即可登录的管理员账户,并注册了即使在插件卸载后仍能持续
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WPManageNinja | Fluent Forms Pro | 6.2.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WPManageNinja | Fluent Forms Pro | 6.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73533 | 9.8 CRITICAL | Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build |
| CVE-2026-18146 | 7.2 HIGH | Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smar |
| CVE-2026-66467 | 6.5 MEDIUM | WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability |
No comments yet