PT-2025-33523 · WordPress · Wpgym - Wordpress Gym Management System

Friderika Baranyai

·

Published

2025-08-16

·

Updated

2025-08-21

·

CVE-2025-6080

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WPGYM - Wordpress Gym Management System plugin versions prior to 67.7.1
Description: The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation. This is due to the plugin not properly validating a user's capabilities prior to adding users, allowing authenticated attackers with Subscriber-level access and above to create new users, including administrators.
Recommendations: Update the WPGYM - Wordpress Gym Management System plugin to version 67.7.1 or later.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-6080

Affected Products

Wpgym - Wordpress Gym Management System