All 6 CVE vulnerabilities found in WPGYM - Wordpress Gym Management System, with AI-generated Chinese analysis, references, and POCs.
Vendor: dasinfomedia
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-7049 | WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover CWE-639 | 8.8 | High | 2025-09-10 |
| CVE-2025-6080 | WPGYM <= 67.7.0 - Missing Authorization to Admin Account Creation CWE-269 | 8.8 | High | 2025-08-16 |
| CVE-2025-3671 | WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update CWE-22 | 8.8 | High | 2025-08-16 |
| CVE-2025-7442 | WPGYM - Wordpress Gym Management System < 67.8.0 - Unauthenticated SQL Injection CWE-89 | 7.5 | High | 2025-07-11 |
| CVE-2024-9941 | WPGYM <= 67.1.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation CWE-269 | 8.8 | High | 2024-11-23 |
| CVE-2024-9942 | WPGYM <= 67.1.0 - Unauthenticated Arbitrary File Upload CWE-434 | 9.8 | Critical | 2024-11-23 |
All 6 known CVE vulnerabilities affecting WPGYM - Wordpress Gym Management System with full Chinese analysis, references, and POCs where available.