The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities prior to adding users. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new users, including admins.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 16 Aug 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities prior to adding users. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new users, including admins. | |
Title | WPGYM <= 67.7.0 - Missing Authorization to Admin Account Creation | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-08-16T03:38:50.216Z
Updated: 2025-08-18T19:00:07.097Z
Reserved: 2025-06-13T17:08:37.410Z
Link: CVE-2025-6080

Updated: 2025-08-18T13:36:46.116Z

Status : Awaiting Analysis
Published: 2025-08-16T04:15:58.867
Modified: 2025-08-18T20:16:28.750
Link: CVE-2025-6080

No data.