CVE-2025-2505
Age Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang'
Record summary
CVE-2025-2505 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 19, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Age Gate plugin for WordPressBrowse Age Gate / Age Gate plugin for WordPress | VulnCheck | Version data not supplied | |
Age GateBrowse philsbury / Age GateDefault status: unaffected | CVE List | Through 3.5.3 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress Age Gate <= 3.5.3 - Unauthenticated Local File InclusionCVSS 9.8
The Age Gate plugin for WordPress up to version 3.5.3 contains a local PHP file inclusion caused by the 'lang' parameter, letting unauthenticated attackers include and execute arbitrary PHP files, exploit requires no authentication.
Impact
Attackers can execute arbitrary PHP code on the server, potentially leading to full server compromise.
Remediation
Update to the latest version of the plugin, version 3.5.4 or later.
Source: ProjectDiscovery