Known CVE
WP User Manager – User Profile Builder & Membership - Local File Inclusion
WP User Manager – User Profile Builder & Membership plugin for WordPress <= 2.9.17 contains a local file inclusion caused by improper handling in the profile template scope function, letting unauthenticated attackers execute arbitrary PHP code, exploit requires ability to upload or control PHP files.
CVE-2026-9290
High2026CVSS 7.5CWE-22
cve2026 · wordpress · wp-plugin · wp-user-manager · lfi · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website