CVE-2024-9941

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new user accounts with the administrator role.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mojoomla:wordpress_gym_management_system:*:*:*:*:*:wordpress:*:*

History

26 Nov 2024, 19:37

Type Values Removed Values Added
CPE cpe:2.3:a:mojoomla:wordpress_gym_management_system:*:*:*:*:*:wordpress:*:*
CWE CWE-862
First Time Mojoomla
Mojoomla wordpress Gym Management System
Summary
  • (es) El complemento WPGYM - Wordpress Gym Management System para WordPress es vulnerable a la escalada de privilegios debido a una verificación de capacidad faltante en la función MJ_gmgt_add_staff_member() en todas las versiones hasta la 67.1.0 incluida. Esto permite que atacantes autenticados, con acceso de nivel de suscriptor y superior, creen nuevas cuentas de usuario con el rol de administrador.
References () https://codecanyon.net/item/-wpgym-wordpress-gym-management-system/13352964 - () https://codecanyon.net/item/-wpgym-wordpress-gym-management-system/13352964 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/cbff92c1-8492-4d0d-bd90-8fd33625bf6f?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/cbff92c1-8492-4d0d-bd90-8fd33625bf6f?source=cve - Third Party Advisory

23 Nov 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-23 08:15

Updated : 2024-11-26 19:37


NVD link : CVE-2024-9941

Mitre link : CVE-2024-9941

CVE.ORG link : CVE-2024-9941


JSON object : View

Products Affected

mojoomla

  • wordpress_gym_management_system
CWE
CWE-269

Improper Privilege Management

CWE-862

Missing Authorization