CVE-2026-9290 is an unauthenticated local file inclusion vulnerability in the WP User Manager – User Profile Builder & Membership plugin for WordPress affecting all versions up to and including 2.9.17. The flaw arises from improper validation of a user-controlled profile tab parameter in the plugin’s profile template-loading workflow. According to the available technical details, the tab value is read by the profile tab selection logic, propagated through permalink and routing code, and ultimately used by the template loader to construct a path for a template partial without sufficient restriction to an approved set of values. This allows a remote attacker to use directory traversal sequences to include arbitrary files from the local filesystem. Where included files contain executable PHP code, the vulnerability can result in execution of that code in the web server context. The issue is fixed in version 2.9.18 through whitelist validation of profile and account tab input.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit project for the claimed CVE-2026-9290 affecting the WordPress WP User Manager plugin. The repo contains 4 files: a main Python exploit script (cve_2026_9290.py), a README with vulnerability explanation and usage examples, a requirements.txt listing requests and urllib3, and a .gitignore. The exploit is not part of a larger framework. The main capability is unauthenticated web-based LFI via the tab query parameter on WP User Manager profile pages. The script first detects the plugin by requesting known plugin files under /wp-content/plugins/wp-user-manager/, then attempts to locate a profile/account endpoint from a hardcoded list or by scraping homepage links. It then sends crafted requests with traversal payloads intended to include local files such as wp-config.php or /etc/passwd. The code supports single-target and mass-target scanning, multithreading, verbose output, and saving results. The exploit goes beyond pure detection because it attempts to retrieve file contents and report previews, so it is a real exploit rather than only a detector. However, the RCE aspect is only a chained possibility: the script enumerates likely include targets such as uploads and log files, but it does not itself upload a PHP shell, poison logs, or execute commands. As a result, the repository is best characterized as an operational LFI exploit with RCE-path probing rather than a full end-to-end RCE weapon. Fingerprintable targets and paths are abundant in the code: plugin detection paths, candidate profile endpoints, the vulnerable tab parameter, and several local filesystem traversal targets including wp-config.php, plugin PHP files, uploads, debug.log, and common Apache/httpd access logs. The overall purpose of the repository is to automate discovery and exploitation of the vulnerable WP User Manager include path handling to confirm LFI and identify possible follow-on RCE opportunities.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
An unauthenticated local file inclusion and path traversal vulnerability in the WP User Manager WordPress plugin that allows remote attackers to include arbitrary PHP files via the tab query parameter, potentially exposing sensitive files and enabling remote code execution if an attacker can upload a PHP file.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.