Access violation vulnerability in WPGYM – WordPress Gym Management System 67.7.0

The WPGYM plugin for WordPress, which is used to manage gyms, has a security vulnerability in all versions up to 67.7.0. This vulnerability, known as Local File Inclusion, allows authenticated attackers with at least Subscriber-level access to include and run any files on the server. This can lead to bypassing security controls, accessing sensitive information, and even executing malicious code. The exploit can also be used to update the password of Super Administrator accounts in Multisite environments, potentially giving attackers more privileges.

Detected in:

WPGYM - Wordpress Gym Management System open vulnerable versions: >= * <= 67.7.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.