If you run Fluent Forms Pro or Ninja Tables Pro and updated your site on July 31, check for rogue admin accounts now. Attackers slipped backdoored versions of both plugins through WPManageNinja’s own official update system for about five hours.
What happened
WPManageNinja had migrated its store and licensing system off Easy Digital Downloads onto its own platform, but left the old EDD server running. Its update proxy, the system that decides which server answers each update request, kept routing some traffic to that decommissioned machine. An attacker broke into the forgotten server and swapped in tampered files.
Between 14:00 and 19:00 UTC on July 31, sites that requested an update, including those with auto-updates turned on, could have received a backdoored copy of Fluent Forms Pro 6.2.7 or Ninja Tables Pro 5.2.11 instead of the real thing. Because the update came through WPManageNinja’s own legitimate infrastructure, there was nothing unusual for a site owner to notice. Founder Shahjahan Jewel disclosed the incident in a detailed post-mortem published August 1.
The tampered code creates a rogue administrator account, drops backdoor files into wp-content/mu-plugins/ and wp-content/uploads/, opens a REST API endpoint for remote control, and sets up scheduled tasks to keep itself running. It also adds the rogue admin account to the allowlists of common security plugins, which suppresses the new-admin alerts that would normally flag the intrusion. Files placed in mu-plugins load automatically on every page request, don’t show up in your plugin list, and survive a normal plugin deletion, which makes this backdoor unusually hard to spot and remove.
Who is at risk
WPManageNinja emailed 1,368 customers whose sites requested either plugin on July 30 or 31. The company’s own checks suggest around 295 of those accounts actually received the tampered files, but it chose to notify everyone in the larger group because its logs can’t distinguish who got the clean version from who got the backdoored one.
What to do
Update to the current clean release of Fluent Forms Pro or Ninja Tables Pro immediately. Check your WordPress admin users list for accounts you don’t recognize, and look inside wp-content/mu-plugins/ and wp-content/uploads/ for files you didn’t put there. WPManageNinja’s post-mortem lists specific indicators of compromise and step-by-step cleanup instructions, and the company is offering free cleanup help to affected customers.
End of article