Unauthenticated File Upload Vulnerability in WPGYM Plugin Could Lead to Remote Code Execution
CVE-2024-9942
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 23 November 2024
What is CVE-2024-9942?
The WPGYM - WordPress Gym Management System plugin contains a significant vulnerability due to inadequate file type validation within the MJ_gmgt_user_avatar_image_upload() function. This flaw allows unauthenticated attackers to upload arbitrary files to the server hosting the affected WordPress site. Such unauthorized uploads can lead to various security threats including remote code execution, exposing websites to further attacks. All versions of the WPGYM plugin up to and including 67.1.0 are affected, necessitating immediate attention to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published