Record summary

CVE-2025-2505 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 19, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unaffected

CVE ListThrough 3.5.3affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Age Gate <= 3.5.3 - Unauthenticated Local File InclusionCVSS 9.8

The Age Gate plugin for WordPress up to version 3.5.3 contains a local PHP file inclusion caused by the 'lang' parameter, letting unauthenticated attackers include and execute arbitrary PHP files, exploit requires no authentication.

Impact

Attackers can execute arbitrary PHP code on the server, potentially leading to full server compromise.

Remediation

Update to the latest version of the plugin, version 3.5.4 or later.

WeaknessesCWE-98
Authorspussycat0x
Template tagscvecve2025wordpresswp-pluginage-gatelfiwpvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

4