WPGYM - Wordpress Gym Management System

WPGYM - Wordpress Gym Management System has 10 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2025; 4 are fixed and 6 remain unpatched as of September 2026. Their average CVSS score is 8.4, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 8 high. 2025 was the busiest year with 7 disclosures.

The most common weakness is SQL Injection, behind 4 of the records (40%). Other recurring categories include Improper Privilege Management, Authorization Bypass Through User-Controlled Key.

4 of the records (40%) have a vendor fix, while 6 remain unpatched. The oldest unresolved one dates back to 2017.

8 independent researchers contributed these findings, most of them (2) reported by Tonn.

Strategic Overview

Avg CVSSHigh
8.4/ 10
Patch Coverage40%
Open

6

Fixed

4

Get automatic notifications for all WPGYM - Wordpress Gym Management System vulnerabilities before they are exploited.

Most severe open issueCVSS 8.8CVE-2025-7049

WPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover

Read the full analysis

Vulnerability Records

10 records
2025-09-09 17:42CVE-2025-7049
8.8
High
Michelle PorterNo
2025-08-15 14:56CVE-2025-3671
8.8
High
Trương Hữu Phúc (truonghuuphuc)No
2025-08-15 14:55CVE-2025-6080
8.8
High
FoxyyyNo
2025-07-10 19:17CVE-2025-7442
7.5
High
Trương Hữu Phúc (truonghuuphuc)Yes
2025-07-08 00:00CVE-2025-32574
6.5
Medium
FrankNo
2025-06-12 00:00CVE-2025-32549
8.8
High
AnnnNo
2025-05-16 00:00CVE-2025-32643
7.5
High
BondsYes
2024-11-22 19:12CVE-2024-9942
9.8
Critical
TonnYes
2024-11-22 00:00CVE-2024-9941
8.8
High
TonnYes
2017-09-26 00:00CVE-2017-14844
8.8
High
Ihsan SencanNo
Showing 1–10 of 10 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C