Fluent Forms Pro and Ninja Tables Pro Security Incident Checklist
August 13, 2026
WPManageNinja has reported that Fluent Forms Pro 6.2.7 and Ninja Tables Pro 5.2.11 were tampered builds. The vendor has issued current releases, and the National Vulnerability Database now records the incident as CVE-2026-73532 and CVE-2026-73533. This is a practical, defensive checklist for WordPress owners and agencies that need to identify affected sites, move them to the vendor’s current Pro releases, and obtain the right cleanup help.
Do not assume that a normal plugin update alone closes the incident. WPManageNinja says that sites which received the affected builds should still be checked, including sites that subsequently received a clean update. Keep the response controlled: establish scope, use the vendor’s support path, and avoid improvised production changes.
Which WordPress sites need review
Prioritize a review when a site uses either affected Pro product, especially if it updated during the vendor’s stated July 31 and August 1 incident window. Include agency-managed sites, staging sites that might later be promoted, and sites with automatic plugin updates.
- Fluent Forms Pro 6.2.7 is the vendor-identified affected release; WPManageNinja identifies 6.2.10 as the current release in its incident notice.
- Ninja Tables Pro 5.2.11 is the vendor-identified affected release; WPManageNinja identifies 5.2.14 as the current release in its incident notice.
- The free-plugin listings in the WordPress directory do not establish which Pro release a site has used. Check the licensed Pro product and the site’s own change history.
- Do not treat a site as out of scope solely because the update was automatic or because a site appears to work normally.
Start with a calm ownership and scope check
- Assign one site owner to coordinate the review and record which of the two Pro products is present.
- Note the installed Pro version, the most recent update date, and the person or agency responsible for the license.
- Check the vendor’s security incident notice before scheduling remediation so the team is following the vendor’s latest guidance.
- Keep unrelated core, theme, cache, hosting, and design changes out of the response window until the affected plugin work is understood.
Move to the current vendor release
For an affected Pro product, use the authorized WPManageNinja update channel to install the current release named in the vendor notice. Record the release, time, and responsible owner in the change record. The usual WordPress plugin update guide can help keep the standard maintenance steps organized, but this incident requires the additional vendor review below.
Do not substitute an unverified download, a similarly named free plugin, or an old local copy for the vendor’s current Pro release. If the license owner cannot access the correct release, pause and use the vendor’s support channel rather than guessing.
Use the vendor-supported cleanup path
WPManageNinja asks affected customers to check their sites and offers support for cleanup. Follow that vendor-supported path for a site that may have received an affected build. Do not publish, copy, or run technical remediation material from unverified third parties, and do not make unreviewed direct changes to a live site’s files or database.
Give the support team only the site and update information it requests through its documented channel. Keep customer data, credentials, private support records, and any internal review evidence out of public tickets and general project notes.
Complete the WordPress follow-up
- Review authorized WordPress administrator access through the site’s normal governance process and remove access that is no longer approved.
- Rotate relevant credentials according to the site’s existing incident and access-control policy.
- Confirm important forms, tables, checkout, account, content-editing, and support workflows still behave normally after the vendor-guided work.
- Keep the final scope, vendor case reference, owner, and verification result with the site’s private maintenance record.
For a broader owner-level view of third-party WordPress incidents, see the WordPress plugin supply-chain safety checklist. More recovery, maintenance, and troubleshooting guides live in the Fix I.T. Phill WordPress Support hub.
Fluent Forms Pro and Ninja Tables Pro incident FAQ
Does updating to a current release finish the response?
No. The vendor says sites that subsequently updated should still be checked. Update first, then use the vendor-supported review and cleanup process for a site that may have received an affected build.
Can the free WordPress.org plugin version tell me whether a Pro site is affected?
No. The vendor’s incident notice identifies specific Pro releases. Use the licensed Pro product and the site’s update history to determine whether review is needed.
Should I take the site offline immediately?
Make that decision through the site’s documented incident process with the responsible owner. A careful, vendor-guided review is more useful than an unplanned change that disrupts customers or loses evidence needed for support.
Where are the official references?
Start with WPManageNinja’s incident notice and the National Vulnerability Database entries for CVE-2026-73532 and CVE-2026-73533.

