Extension WordPress
Vulnérabilités WPGYM – Wordpress Gym Management System
Cette page rassemble les failles publiées pour WPGYM – Wordpress Gym Management System, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPGYM – Wordpress Gym Management System
10 fiches
WPGYM – Wordpress Gym Management System <= 67.7.0 – Authenticated (Subscriber+) Privilege Escalation via Account Takeover
The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_add_user' function due to missing validation on a user controlled key. This makes…
*-67.7.0
Non indiqué
09/09/2025
WPGYM – Wordpress Gym Management System <= 67.7.0 – Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update
The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access…
*-67.7.0
Non indiqué
15/08/2025
WPGYM <= 67.7.0 – Missing Authorization to Admin Account Creation
The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities prior…
*-67.7.0
Non indiqué
15/08/2025
WPGYM – Wordpress Gym Management System < 67.8.0 – Unauthenticated SQL Injection
The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters in the MJ_gmgt_delete_class_limit_for_member, MJ_gmgt_get_yearly_income_expense, MJ_gmgt_get_monthly_income_expense, MJ_gmgt_add_class_limit, MJ_gmgt_view_meeting_detail, and MJ_gmgt_create_meeting functions in all versions up to 67.8.0 due to insufficient escaping…
[*, 67.8.0)
67.8.0
10/07/2025
WPGYM <= 65.0 – Authenticated (Subscriber+) SQL Injection
The WPGYM plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 65.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-65.0
Non indiqué
08/07/2025
WPGYM <= 65.0 – Authenticated (Subscriber+) Local File Inclusion
The WPGYM plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 65.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the…
*-65.0
Non indiqué
12/06/2025
WPGYM < 67.8.0 – Unauthenticated SQL Injection
The WPGYM plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 67.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
[*, 67.8.0)
67.8.0
16/05/2025
WPGYM <= 67.1.0 – Unauthenticated Arbitrary File Upload
The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible…
*-67.1.0
67.2.0
22/11/2024
WPGYM <= 67.1.0 – Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
The WPGYM – Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for…
*-67.1.0
67.2.0
22/11/2024
WPGYM – Wordpress Gym Management System (Unknown Version) – SQL Injection
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
*
Non indiqué
26/09/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.