Description
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Published: 2026-06-05
Score: 7.5 High
EPSS: 2.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP User Manager – User Profile Builder & Membership plugin contains an unauthenticated path‑traversal vulnerability that allows local file inclusion. By manipulating the 'tab' query parameter the plugin can include arbitrary files on the server, causing any PHP code within those files to be executed. This flaw enables attackers to bypass access controls, exfiltrate sensitive data, or fully compromise the WordPress installation if PHP files can be uploaded or accessed within the site’s file system.

Affected Systems

Any WordPress installation running WP User Manager up to and including version 2.9.17 is affected. The vulnerability resides in the plugin’s function that processes profile template scope. Administrators of sites using these plugin versions should verify the exact version and note that any release earlier than 2.9.18 is vulnerable.

Risk and Exploitability

The vulnerability received a CVSS score of 7.5, indicating a substantial risk once exploited. The EPSS score is 2%, and the flaw is not currently listed in CISA’s KEV catalog. The likely attack vector is remote, involving a crafted HTTP request to the plugin’s endpoint using the 'tab' parameter. While the vulnerability is unauthenticated, its exploitation would require the attacker to be able to trigger the file inclusion, which can be accomplished by requesting any existing file path or by uploading a PHP file that the site later includes. Attackers could thus read sensitive files or execute arbitrary code on the server.

Generated by OpenCVE AI on June 18, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP User Manager to the latest release (≥ 2.9.18) to apply the vendor’s fix.
  • If an immediate upgrade is impossible, block the 'tab' query parameter or disable the file‑inclusion logic, and ensure that the uploads directory cannot execute PHP files by adjusting web‑server permissions or .htaccess settings.
  • Deploy a web‑application firewall or modify the site’s security rules to detect and prevent path‑traversal attempts and to deny remote access to the vulnerable endpoint.

Generated by OpenCVE AI on June 18, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 07 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpusermanager
Wpusermanager wp User Manager – User Profile Builder & Membership
Vendors & Products Wordpress
Wordpress wordpress
Wpusermanager
Wpusermanager wp User Manager – User Profile Builder & Membership

Sat, 06 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 06 Jun 2026 00:00:00 +0000

Type Values Removed Values Added
Description The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Title WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Wpusermanager Wp User Manager – User Profile Builder & Membership
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-06T11:49:17.970Z

Reserved: 2026-05-22T16:52:45.960Z

Link: CVE-2026-9290

cve-icon Vulnrichment

Updated: 2026-06-06T11:49:13.315Z

cve-icon NVD

Status : Deferred

Published: 2026-06-06T00:16:42.303

Modified: 2026-06-08T14:57:14.757

Link: CVE-2026-9290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T07:30:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')