CYBERHAWK / CVE / CVE-2026-9290

CVE-2026-9290

HIGH CVSS 7.5 other

The flaw

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenti

What to do

Review advisory and patch per vendor guidance.

▸ Scan my repo for CVE-2026-9290

References

First seen 2026-06-12 · Tracked by PickBits CyberHawk · Weekly CVE digest