Security incident - 31 July 2026
Important security notice for Fluent Forms Pro and Ninja Tables Pro users.
On 31 July, tampered versions of Fluent Forms Pro 6.2.7 and Ninja Tables Pro 5.2.11 were served through an old server of ours that should have been shut down long ago. The bad files were live for about five hours, 14:00 to 19:00 UTC. If either plugin updated on your site in that window, including auto-updates, it may have pulled files with code we did not write.
We emailed 1,368 customers, everyone whose site downloaded either plugin on 30 or 31 July. Our checks indicate that around 295 accounts actually received the tampered files, but we have extended the timeframe just to make sure, we are not missing anyone to send the notice. If you did not get an email from us, your site is very likely not involved.
What to do:
-
Move to the clean builds: Fluent Forms Pro 6.2.8 and Ninja Tables Pro 5.2.13.
-
Delete the plugin and install a fresh copy from your account. Do not just deactivate. Your forms, entries, tables and settings live in the database, so nothing is lost.
-
Check for admin users you did not create, unknown .php files in wp-content/uploads, and cron events you do not recognise.
I have written up the whole thing: what happened, who is affected, and what we have already fixed: https://wpmanageninja.com/security-incident-on-31-july-2026/
If you want help cleaning up a site, email contact_support [at] wpmanageninja.com. We will move you to the front of the queue.
We let you down here, and I am sorry. We are fixing the things that made this possible, and I would rather tell you about it plainly than quietly move on.
Just to confirm, when you refer to Fluent Forms Pro 6.2.7, does that also include the plugin listed in WordPress as βFluent Forms Pro Add-On Packβ? Itβs still showing version 6.2.7.
And one quick clarification: if we did not receive the direct incident email from WPManageNinja, can we reasonably assume that our sites were not among those that downloaded either affected plugin on 30 or 31 July, or should we still treat it as potentially affected?
We will carry out a full audit anyway, but I wanted to clarify those two points. Thanks, Jewel!
Jorge de los ReyesΒ So we log all the downloads per customer. So if you did not get any email, that means you are not affected. Only around 300 customers got affected but we sent email all the customers who downloaded in the last 2 days. and yes
Fluent Forms Pro Add-On Pack -> That's the pro.
Shahjahan JewelΒ Thanks Jewel. That clears it up.
Thank you as well for confirming that βFluent Forms Pro Add-On Packβ is the Pro plugin referred to in the notice. We will still carry out a precautionary audit and install the latest clean release, but your clarification is very reassuring.
I really appreciate the transparency and the quick response!
Customer area is disabled. I wanted to download the pro version, but can't ... What to do now? I am confused, Shahjahan JewelΒ
Nicole Y. MΓ€nnl - NY DigitalΒ we wanted to make sure everything is alright. So we did a full forensic test. You can access now.
Shahjahan JewelΒ I made a "forensic" audit to my sites and everything's OK.
Thanks for the fast manage of the incident and the support π
Jose Luis DuronΒ Aorry the the hassle man. I really feeling down today and I think the worst day in my whole entrepreneurial journey. But we are trying to keep it as transparent and letting the affecting customers know as soon a spossible. We just sent round 2 emails.
Shahjahan JewelΒ please donβt let this ruin your weekend. These things happen, and they give you an opportunity to strengthen security, protocols, etc. People seem to be pretty understanding about it too. Weβll be right here using Fluent products, ready to buy whatβs next!
Shahjahan JewelΒ The most important thing is that you took action, and you did the right thing by communicating quickly and transparently. You can relax now. The hardest part is over. Whatever happens, you'll come out of this stronger!
Dragan STAMENKOVICΒ I completely agree with all of the above. Thank you for the transparency and quick resolution!
Are points 2-4 really necessary? Just asking cause that's a lot of work on 4 different Community sites fully setup and functioning.
I got the email and it listed only 1 of my 4 sites that was affected by this. I've already download, installed, activated the fix, scan & cleanup plugin completely, but I didn't do steps 2-4 yet. I'm actually hoping this isn't needed. I just need to know from those with more experience at this than myself if this is something I NEEDS/MUST do ASAP?
David ForeΒ I think it's said, if you regenerate the salts, then you have reconfigure the SMTP for fluent-smtp as that generated. And yes, for 99% of the cases that not need. But this is what you can do:
- Go to FluentSMTP and then disable encryption
- Come back to the cleaner plugin and regenerate the salts, login again and then enable the encryption.
Shahjahan JewelΒ Ok, I'm sorry, I have no idea what a "salts" is or does. And I don't know if the fix plugin you linked to in the email did anything with the "salts" or not.
David ForeΒ Salts are encryption keys for your login hashes and FluentSMTP if you are using, uses to encrypt the api keys.
Okay Shahjahan JewelΒ got it now ..l was freaking out!
Is fluentformpro-6.2.10.zip safe to download from our account now Shahjahan JewelΒ
Shahjahan JewelΒ Thanks π
Thank you!
So if I understand correctly, if we updated to Fluent Forms Pro to 6.2.7 on July 18 and Ninja Tables Pro to 5.2.11 on July 23 already, (and updated later to 6.2.9 and 5.2.14), we are not affected at all, right? (as the bad build were only available on July 31 for a few hours?)
Patricia BTΒ Exactly that's right. Also if you are affected, you would get an email from us. As we send emails to everyone who downloaded within 24 hours of the incident just to make sure nobody is left behind to take action.
I read the whole article, Appreciate the honesty and that is why I like WP Manage Ninja.
I would also like to know what is the actual treat , and how can we check even though we have updated it to the latest version, I would like to make sure that affected code is not on my sites..
Could you please advise:
- How can we verify with confidence that a site was not compromised?
- Are there any indicators of compromise (IOCs), file paths, database entries, cron jobs, or other artefacts we should check?
- Is there an official scanning tool or verification script you recommend?
- Is reinstalling the latest plugin sufficient, or are there additional remediation steps you recommend for sites that may have installed an affected version?
Thank you for your kind words and for taking the time to read our incident report. We truly appreciate your trust and understanding.
The primary risk is that the compromised package could implant a backdoor on the affected site. Even after updating to the latest version, simply updating the plugin would not remove any malicious files if a site had already been affected.
To help customers verify their sites, we have released an official cleanup and verification plugin. We recommend running it even if you have already updated to the latest version. The scanner will check for known indicators of compromise and automatically remove any affected files if they are found.
You can download the scanner here:
https://wpmanageninja.com/wp-content/uploads/2026/08/ffir-incident-response.zip
Please follow this short video guide:
https://drive.google.com/file/d/1FOCnnbWT-V3BQn5vdG3PpbI5cg8jLhhj/view?usp=sharing
If the scanner reports no issues, you can be confident that your site was not affected by this incident. If it detects anything, it will automatically perform the necessary cleanup. Afterward, we recommend ensuring you are running the latest clean version of the plugin, which can be downloaded from your WPManageNinja Dashboard.
At this time, we recommend using the official scanner rather than manually checking for IOCs, as it is designed specifically to detect and remediate the known artifacts related to this incident.
Is running with the default checkboxes selected good enough? Shahjahan JewelΒ thanks
Sella YoffeΒ yes that's good enough.
Shahjahan JewelΒ great. thank you! Appreciate your transparency, solution and fast response to this incident.
Thank you for getting info out to everyone quickly, and for being transparent about what happened.
Sharon CΒ Thanks for being kind. We are trying everything to help the affected customers; also, we are making sure it never happens.
will updating the plugin through Wordpress be ok, or do we have to deactivate, and install new downloaded version? Will the forms we have created be preserved?
Rob HΒ So the free core version is not affected. The affected version the pro version. So you should delete the pro versions, download fresh from our site and install.
I've noticed that the email you sent me indicates that the incident is limited to the specific sites mentioned in your message.
However, when I checked another site that wasn't on that list, it appears to be infected as well.
Sella YoffeΒ If you are using shared hosting, the site can be infected by the child sites. Please note that we have notified all the customers who got update from our site; we could not confirm if it was manually uploaded. We have released the core version, which will detect and deactivate the pro automatically if it's infected.
Shahjahan Jewel I'm not using shared hosting, but it looks like this site is using a Fluent Forms license that's not under my account. So it was probably just a false alarm on my end. Anyway, just out of curiosity, I'll run the check on all my sites.
Thank you very much.
Shahjahan JewelΒ This brings me to question all of my sites. I currently have 4 separate FluentCommunity sites all running on the same xCloud Managed VPS, so should I install and run your "ffir" plugin on all of my sites? I'm using 94% of all your Fluent Plugins on all my sites, some paid versions some not.
Just wondering if I should do this on all of my sites or just the one you specifically mentioned in the email?