WPGYM
cpe:2.3:a:dasinfomedia:wpgym_gym_management_system:*:*:*:*:wordpress:*:*
- <= 67.7.0
A privilege escalation vulnerability has been identified in the WPGYM - WordPress Gym Management System plugin, affecting all versions through 67.7.0. The issue arises in the 'MJ_gmgt_gmgt_add_user' function, where insufficient validation of a user-controlled key allows authenticated attackers with Subscriber-level access or higher to modify the email, password, and other details of any user, including those with Administrator privileges.
Exploitation of this vulnerability allows for unauthorized changes to user account details, potentially leading to account takeover, especially for Administrator users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.