WPManageNinja Discloses Supply Chain Attack Affecting Fluent Forms Pro and Ninja Tables Pro

  • News

WPManageNinja has disclosed a security incident in which an old server that remained connected to its plugin update infrastructure distributed tampered versions of Fluent Forms Pro and Ninja Tables Pro for about five hours on July 31, 2026.

The company said Fluent Forms Pro 6.2.7 and Ninja Tables Pro 5.2.11 were affected, with around 295 customer accounts downloading a tampered version. WPManageNinja said it contacted 1,368 customers whose sites downloaded either plugin around the time of the incident.

How an old server and leftover routing rules led to the incident

The incident traces back to infrastructure WPManageNinja had left behind after moving its store and licensing system away from Easy Digital Downloads (EDD). Shahjahan Jewel, founder of WPManageNinja LLC, said the old server remained running, while some proxy routing rules continued sending some plugin update requests to it.

An attacker gained access to the old server and changed the files it returned. Because the proxy was still routing some update traffic there, the modified files were passed on to customer sites as normal plugin updates.

Jewel acknowledged WPManageNinja’s responsibility for the incident, saying the old server should have been shut down when the company completed its migration away from EDD and that the routing rules pointing to it should have been removed at the same time. “This was our fault. That old server should have been switched off when we finished migrating away from EDD, and the routing rules that still pointed at it should have gone with it.”

The affected releases were Fluent Forms Pro 6.2.7 and Ninja Tables Pro 5.2.11. Jewel said, “The files looked normal but had extra code added to them.” Sites with automatic updates enabled could also receive the modified files without any manual action.

WPManageNinja said it detected the issue on the same day, stopped the update, removed the attacker’s access and changed the relevant credentials. The company also removed the remaining proxy routing rules and shut down the old server. Clean builds of both plugins were released that evening.

The company said around 295 customer accounts downloaded a tampered version. It emailed 1,368 customers whose sites downloaded either plugin on July 30 or 31.

Jewel said the company’s download records show which sites requested a file and when, but do not show exactly which copy of the file each site received. This was why the company notified customers who downloaded either plugin during the two-day period rather than limiting the emails to the accounts it could identify as having received the tampered versions.

As Jewel explained, “We could have emailed only those 295 people. We chose not to.” He said the company emailed every customer whose site downloaded either plugin on July 30 or 31.

They published checks for customers to determine whether their sites received a tampered version. These include checking the installed plugin versions and looking for files that should not be present in legitimate releases.

For Fluent Forms Pro, the file identified by the company is libs/class-license-sync.php, located under the fluentformpro/ plugin directory. For Ninja Tables Pro, it is app/Library/updater/NinjaTableDataSync.php, in the ninja-tables-pro folder. WPManageNinja said neither file exists in any legitimate release it has shipped.

WPManageNinja also provided a database query that customers can use to search for apii.observer in the wp_options table. Its instructions also tell customers to look for the scheduled tasks wp_update_check_schedule and wp_license_verify_schedule, and to test the /wp-update/v1/check REST route: “A 404 is what you want. Any other response means the code is active.”

Customers are also told to check for administrator accounts they cannot identify, particularly accounts registered on or after July 31, 2026. WPManageNinja says to check wp-content/mu-plugins even if the directory has never been used, because anything in it loads automatically on every request and does not appear in the plugin list. The company also tells customers to look for PHP files anywhere under wp-content/uploads.

WPManageNinja is offering customers assistance with cleanup at no cost and said the help does not count against their support limits. Customers who are unsure about the results of the checks are also encouraged to contact the company for help.

Jewel said, “We are still going through the changed files and our server logs.” He added, “If we find anything that changes the advice above, I will update this post and say what changed and when.”

Community backs WPManageNinja after incident

The incident also drew supportive responses from members of the Fluent Forms community after Jewel spoke about how the incident had affected him.

After Jose Luis Duron said he had carried out a “forensic” audit of his sites and found everything was fine, Jewel apologized for the hassle and said, “I really feeling down today and I think the worst day in my whole entrepreneurial journey.” He also said the company was trying to remain transparent and notify affected customers as soon as possible.

Kaneisha G. responded by telling Jewel, “please don’t let this ruin your weekend,” adding that incidents like this could provide an opportunity to strengthen security and protocols. She also said, “We’ll be right here using Fluent products, ready to buy what’s next!”

Dragan Stamenkovic similarly praised the company’s response, saying, “The most important thing is that you took action, and you did the right thing by communicating quickly and transparently.” Teddy Skokos agreed, thanking the company for its “transparency and quick resolution.”

Jewel later thanked customers for their support and said the company was “trying everything to help the affected customers” while also working to make sure such an incident never happens again.

Other notable WordPress plugin security incidents this year

In June, five Awesome Motive products were involved in security incidents, involving Uncanny Automator, OptinMonster, TrustPulse, PushEngage, and MonsterInsights.

Other incidents reported this year include the temporary closure of more than 80 WPFactory plugins on WordPress.org following a security report involving its EU/UK VAT for WooCommerce Pro plugin, as well as a ShapedPlugin supply chain compromise.

The WP Week Newsletter

Curated updates for agencies, developers, and serious WordPress users. Delivered weekly.

Leave your comment

Your email address will not be published. Required fields are marked *