Mehrere Schwachstellen (CVE-2026-73420, CVE-2026-73421, CVE-2026-73532, CVE-2026-73533, CVE-2026-73842, CVE-2026-73843) in Fluent
⚠️ CVE-Referenzen:
CVE-2026-73420
CVE-2026-73421
CVE-2026-73532
CVE-2026-73533
CVE-2026-73842
CVE-2026-73843
WPmanageninja - Fluent Forms Pro - CRITICAL - CVE-2026-73532.
Fluent Forms Pro version 6.2.7 is impacted by an embedded malicious code vulnerability due to a tampered plugin build deployed via an outdated update server. This manipulation introduced a rogue PHP file, which, when executed, created an insecure REST API endpoint and dropped persistent PHP files within the mu-plugins and uploads directories. Additionally, it installed a passwordless admin account and scheduled tasks that remained active after the removal of the plugin, posing significant risks to site integrity and security.
Quelle: securityvulnerability.io