PT-2024-39954 · WordPress · Wpgym

Tonn

·

Published

2024-11-23

·

Updated

2024-11-26

·

CVE-2024-9941

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPGYM - Wordpress Gym Management System plugin versions up to, and including, 67.1.0
Description The issue is related to a missing capability check on the MJ gmgt add staff member() function, which allows authenticated attackers with subscriber-level access and above to create new user accounts with the administrator role. This enables privilege escalation.
Recommendations For versions up to, and including, 67.1.0, update to a version that includes a fix for the missing capability check on the MJ gmgt add staff member() function. As a temporary workaround, consider restricting access to the MJ gmgt add staff member() function to prevent unauthorized creation of administrator accounts.

Fix

Improper Privilege Management

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-9941

Affected Products

Wpgym