Junglewise Threat Intelligence

CVE-2026-9290: WP User Manager Local File Inclusion in profile template scope

CVE-2026-9290 · Severity: high · CVSS 7.5 · Published 2026-06-06

Technologies: WP User Manager – User Profile Builder & Membership. Vendors: WP User Manager.

Executive brief

WP User Manager, a popular WordPress plugin used for creating member profiles and registration forms, contains a security flaw that allows unauthorized individuals to access internal server files. By exploiting this vulnerability, an attacker could potentially view sensitive data or execute malicious code if they are able to upload a file to the server. This could lead to a full compromise of the website and its user data.

Technical details

The WP User Manager plugin for WordPress is vulnerable to Local File Inclusion (LFI) via the profile template scope function in all versions up to and including 2.9.17. The root cause is a failure to validate the 'tab' query variable against a whitelist of registered tabs before using it in template loading functions like wpum_get_active_profile_tab(). An unauthenticated remote attacker can exploit this by supplying a path to a local PHP file, which the server will then include and execute. This can lead to sensitive information disclosure or remote code execution if the attacker can pair this with a file upload vulnerability. A patch has been developed to validate input against registered profile and account tabs.

Affected products

  • WP User Manager WP User Manager – User Profile Builder & Membership Up to and including 2.9.17

Timeline

  • 2026-05-30: patched: Pull request with security fix merged on GitHub
  • 2026-06-06: disclosed: CVE published to NVD dataset

References