← العودة للجدول
CVE-2026-9290
CVE-2026-9290 — The WP User Manager – User Profile Builder & Membership plugin for WordPre
📅 2026-06-05
🟠 High 🔥 No NVD Exploit Web CVSS 7.5

📋 الوصف الكامل

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypa

💻 الأنظمة المتأثرة

WordPress | PHP

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-9290

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.9.17

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←