Extension WordPress

Vulnérabilités WPGYM – Wordpress Gym Management System

Cette page rassemble les failles publiées pour WPGYM – Wordpress Gym Management System, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
1Critiques
4Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPGYM – Wordpress Gym Management System

10 fiches

CVE-2025-7049 Élevée · 8,8
WPGYM – Wordpress Gym Management System

WPGYM – Wordpress Gym Management System <= 67.7.0 – Authenticated (Subscriber+) Privilege Escalation via Account Takeover

The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_add_user' function due to missing validation on a user controlled key. This makes…

Versions affectées

*-67.7.0

Correctif

Non indiqué

Publication

09/09/2025

CVE-2025-3671 Élevée · 8,8
WPGYM – Wordpress Gym Management System

WPGYM – Wordpress Gym Management System <= 67.7.0 – Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update

The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access…

Versions affectées

*-67.7.0

Correctif

Non indiqué

Publication

15/08/2025

CVE-2025-7442 Élevée · 7,5
WPGYM – Wordpress Gym Management System

WPGYM – Wordpress Gym Management System < 67.8.0 – Unauthenticated SQL Injection

The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters in the MJ_gmgt_delete_class_limit_for_member, MJ_gmgt_get_yearly_income_expense, MJ_gmgt_get_monthly_income_expense, MJ_gmgt_add_class_limit, MJ_gmgt_view_meeting_detail, and MJ_gmgt_create_meeting functions in all versions up to 67.8.0 due to insufficient escaping…

Versions affectées

[*, 67.8.0)

Correctif

67.8.0

Publication

10/07/2025

CVE-2024-9941 Élevée · 8,8
WPGYM – Wordpress Gym Management System

WPGYM <= 67.1.0 – Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for…

Versions affectées

*-67.1.0

Correctif

67.2.0

Publication

22/11/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités