On 31 July 2026, someone served changed versions of two of our plugins through a server of ours that should have been switched off a long time ago. If your site updated during a five hour window that day, it may have downloaded plugin files with code in them that we did not write.
We have emailed every customer whose site downloaded either plugin on 30 or 31 July. If you did not get an email from us, your site is very likely not involved. I am publishing this anyway, because you deserve to see the full story and not just the parts that fit in an email.
The short version
- Fluent Forms Pro 6.2.7 was tampered with. The clean version is 6.2.8.
- Ninja Tables Pro 5.2.11 was tampered with. The clean version is 5.2.13.
- The bad files were available for about five hours, between 14:00 and 19:00 UTC on 31 July 2026.
- We emailed 1,368 customers whose sites downloaded either plugin within 36 hours of the incident.
- Around ~295 customers downloaded the tampered version, but we emailed all the customers who downloaded before and after the timeframe.
- If you are on the clean versions and you have checked your site, you are fine.
What happened
Plugin updates do not come straight from one machine. Update requests hit a proxy, and the proxy decides which server behind it answers each endpoint.
A while back we moved our store and licensing off EDD (Easy Digital Downloads) and onto our own system. When we finished that migration, we left the old server running. We also left routing rules on the proxy that still sent a few endpoints to that old server. Both of those should have been removed when the migration was done. They were not.
Someone got into that old server. Because the proxy was still routing some update traffic there, they did not need to break into our current systems or trick anyone into downloading from a strange place. They changed the files that old server handed back, and the proxy passed them along to customer sites as a normal update.
That is how changed copies of Fluent Forms Pro 6.2.7 and Ninja Tables Pro 5.2.11 ended up on real sites. The files looked normal but had extra code added to them. Any site that updated while those routing rules were live got the changed files. This includes sites with auto-updates turned on, where nobody had to click anything.
I want to be plain about this part. Our customers did nothing wrong and nothing unusual. They updated a plugin the way you are supposed to, and our own routing sent them to a server we had forgotten to switch off.
We noticed it the same day, stopped the update, removed the attacker’s access, and put out clean builds of both plugins.
Who is affected
Your site may be affected if either plugin updated to 6.2.7 or 5.2.11 during those five hours on 31 July 2026. Auto-updates count, and you did not have to do anything unusual for this to reach you.
Two things worth being clear about.
First, our download records show which sites requested a file and when. They do not show exactly which copy of the file each site received. So we cannot look at the time alone and tell you that you are safe. That is why we emailed everyone who downloaded on 30 or 31 July and not only the sites we could match to those five hours. Some people got an email even though their site is fine. We thought that was better than missing someone.
Second, if your site has already auto-updated to the clean version, the bad files are gone. That is good, but it does not undo anything that code may have done while it was running. Please still check your site.
How many sites this actually reached
We emailed 1,368 customers. The real number affected is smaller than that, and we want to be open about the difference.
As of 1 August, our own checks show around 295 customer accounts.
We could have emailed only those 295 people. We chose not to. Our records show which sites asked for a file and when, but not exactly which copy each one received, so drawing a tight line around “definitely affected” would have meant guessing at the edges. That is how somebody gets missed. Instead, we emailed every customer whose site downloaded either plugin on 30 or 31 July, which is 1,368 people. We also considered the network caching, so anyone can get the infected version even after a few hours closing down the server.
Most of them are fine, and their email will turn out to have been unnecessary. We think an unnecessary email is a much smaller problem than a missed one.
These numbers may move as we keep checking. If they do, I will update this post.
What to do
1. Replace the plugin files. Delete the plugin from your site. Do not just deactivate it. Then install a fresh copy from your account at https://wpmanageninja.com/account/. Your forms, entries, tables and settings are stored in the database, so you will not lose them.
2. Check your site for anything odd:
- Admin accounts you did not create. Go to Users, then All Users, and filter by Administrator.
- Files you do not know in
wp-content/uploads/, especially anything ending in.php - Scheduled tasks (cron events) you do not know
- Plugins you did not install, including ones that do not show up in the plugin list
- Changed core files. Re-installing the same WordPress version over the top is the fastest way to be sure.
3. If you find anything, or if your site holds sensitive data:
- Change your WordPress salts and keys in
wp-config.php - Reset all admin passwords
- Look at recent user signups and role changes
- Run a full scan with a security plugin like Wordfence, Patchstack or Sucuri
4. If you run other sites on the same server or hosting account, check those too. If you build sites for clients, please check each one.
What we have done
- Removed the attacker’s access and changed every password and key involved
- Removed the leftover proxy routing rules, so no endpoint reaches that old server
- Shut down the old server for good
- Went through the rest of our routing rules and checked where every endpoint actually goes, in case anything else was left pointing somewhere it should not
- Replaced the bad files with clean builds and released them
- Emailed every customer whose site downloaded either plugin on 30 or 31 July.
- We are planning to add checksum-based updating across all of our plugins.
We are still going through the changed files and our server logs. If we find anything that changes the advice above, I will update this post and say what changed and when.
Timeline (UTC)
| When | What |
|---|---|
| 31 July, around 14:00 | The old server starts handing back changed plugin files, and the proxy passes them on |
| 31 July, around 19:00 | We spot it and take the update offline |
| 31 July, evening | Attacker access removed, credentials changed, proxy routing rules removed, old server shut down |
| 31 July, evening | Clean builds released: Fluent Forms Pro 6.2.8 and Ninja Tables Pro 5.2.13 |
| 1 August (06:00 UTC) | 1,368 affected customers emailed |
| 1 August | This post published |
Getting help
If you think your site is affected and you want help cleaning it up, email contact_support [at] wpmanageninja.com and tell us. We will put you at the front of the queue. There is no cost for this and it does not count against your support limit. If you manage many sites, tell us how many and we will work through them with you.
What I want to say
This was our fault. That old server should have been switched off when we finished migrating away from EDD, and the routing rules that still pointed at it should have gone with it. We left both in place, and someone used them to put code on your sites through a door with our name on it.
You trust us with code that runs on your site. That trust is the whole business. We let you down here, and I am sorry. We are fixing the things that made this possible, and I would rather tell you about it plainly than quietly move on.
If you have questions, write to me at contact_support [at] wpmanageninja.com.
Shahjahan Jewel
Founder, WPManageNinja LLC








Leave a Reply
You must be logged in to post a comment.