CVE-2024-9941

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new user accounts with the administrator role.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mojoomla:wordpress_gym_management_system:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-11-23 08:15

Updated : 2024-11-26 19:37


NVD link : CVE-2024-9941

Mitre link : CVE-2024-9941

CVE.ORG link : CVE-2024-9941


JSON object : View

Products Affected

mojoomla

  • wordpress_gym_management_system
CWE
CWE-269

Improper Privilege Management

CWE-862

Missing Authorization