Access violation vulnerability in WPGYM – WordPress Gym Management System 67.1.0

The WPGYM plugin for WordPress, which helps manage gyms, has a security issue that can allow attackers to gain more privileges than they should have. This can happen because the plugin does not properly check for user permissions when using the MJ_gmgt_add_staff_member() function. As a result, people who are logged in and have at least subscriber-level access can create new user accounts with administrator privileges.

Detected in:

WPGYM - Wordpress Gym Management System open vulnerable versions: >= * <= 67.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.