High 8.8 Unfixed
2025-09-10≤ 67.7.0
WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover
Minimum safe version
67.8.0
Update to 67.8.0 or later to address 4 fixable vulnerabilities
WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover
WPGYM <= 67.7.0 - Missing Authorization to Admin Account Creation
WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update
WordPress WPGYM plugin <= 65.0 - SQL Injection vulnerability
WPGYM - Wordpress Gym Management System < 67.8.0 - Unauthenticated SQL Injection
WordPress WPGYM <= 65.0 - Local File Inclusion Vulnerability
CVE-2025-32643
WordPress WPGYM Plugin <= 67.1.0 is vulnerable to Broken Access Control
CVE-2024-9942
CVE-2017-14844