8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities prior to adding users. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new users, including admins.
Basic Information
ID
CVE-2025-6080
Source
Wordfence
Published
Aug 16, 2025 at 03:38
Affected Product
Vendor
dasinfomedia
Product
WPGYM - Wordpress Gym Management System
Version
*
Affected Versions
dasinfomedia WPGYM - Wordpress Gym Management System *