Age Gate <= 3.5.4 - Missing Authorization
medium
The Age Gate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the store() function in all versions up to, and including, 3.5.4. This makes it possible for unauthenticated attackers to update settings.
- CVSS:
- 5.3
- Affected:
- up to 3.5.4
- Fixed in:
- 3.6.0
- Disclosed:
- Apr 9, 2025
CVE-2025-31012 on NVD →
Age Gate [age-gate] < 3.6.0
unknown
[en] Missing Authorization vulnerability in Phil Age Gate allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Age Gate: from n/a through 3.5.4.
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Apr 9, 2025
CVE-2025-31012 on NVD →
Age Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang'
critical
The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be used...
- CVSS:
- 9.8
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.4
- Disclosed:
- Mar 19, 2025
CVE-2025-2505 on NVD →
Age Gate <= 2.13.4 - Open Redirect
medium
The Age Gate plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 2.13.4 via the '_wp_http_referer' parameter. This makes it possible for unauthenticated attackers to send users redirection links to hostile sites by using the website's address.
- CVSS:
- 4.7
- Affected:
- up to 2.13.5
- Fixed in:
- 2.13.5
- Disclosed:
- Nov 27, 2022
Age Gate [age-gate] < 2.13.5
unknown
The Age Gate plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 2.13.4 via the '_wp_http_referer' parameter. This makes it possible for unauthenticated attackers to send users redirection links to hostile sites by using the website's address.
- Affected:
- up to 2.13.5
- Fixed in:
- 2.13.5
- Disclosed:
- Nov 27, 2022
Age Gate [age-gate] < 2.17.1
unknown
[en] Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Phil Baker's Age Gate plugin <= 2.17.0 at WordPress.
- Affected:
- up to 2.17.1
- Fixed in:
- 2.17.1
- Disclosed:
- Jun 15, 2022
CVE-2021-36901 on NVD →
Age Gate <= 2.17.0 - Cross-Site Scripting via Data Import
high
The Age Gate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data imports in versions up to, and including, 2.17.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...
- CVSS:
- 7.2
- Affected:
- up to 2.17.0
- Fixed in:
- 2.17.1
- Disclosed:
- Jun 10, 2022
CVE-2021-36901 on NVD →
Age Gate [age-gate] < 2.17.1
unknown
Unauthenticated Import Settings vulnerability discovered in WordPress Age Gate (versions <= 2.17.0).
- Affected:
- up to 2.17.1
- Fixed in:
- 2.17.1
- Disclosed:
- Oct 25, 2021
Age Gate <= 2.16.3 - Stored Cross-Site Scripting
medium
The Age Gate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Additional content’ field in versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will ex...
- CVSS:
- 6.4
- Affected:
- up to 2.16.4
- Fixed in:
- 2.16.4
- Disclosed:
- Oct 6, 2021
Age Gate [age-gate] < 2.16.4
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Martin Vierula (Trustwave) in WordPress Age Gate plugin (versions <= 2.16.3).
- Affected:
- up to 2.16.4
- Fixed in:
- 2.16.4
- Disclosed:
- Oct 6, 2021
Age Gate [age-gate] < 2.16.4
unknown
The Age Gate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Additional content’ field in versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will ex...
- Affected:
- up to 2.16.4
- Fixed in:
- 2.16.4
- Disclosed:
- Oct 6, 2021
Age Gate [age-gate] < 2.13.5
unknown
URL Redirection to Untrusted Site ('Open Redirect') vulnerability found by Ilca Lucian Florin in WordPress WordPress Age Gate plugin (versions <= 2.13.4).
- Affected:
- up to 2.13.5
- Fixed in:
- 2.13.5
- Disclosed:
- Nov 30, 2020
Age Gate [age-gate] < 2.20.4
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 2.20.4
- Fixed in:
- 2.20.4
Age Gate [age-gate] < 2.17.1
unknown
The plugin patched an Unauthenticated Import Settings vulnerability. It was found to be exploited in the wild a few days after being patched.
- Affected:
- up to 2.17.1
- Fixed in:
- 2.17.1
Age Gate [age-gate] < 2.16.4
unknown
The plugin does not sanitise and escape the 'Additional content' setting of its 'Messaging' page, which could allow users having access to such setting (by default admin, but the plugin has a feature to change this and allow access to lower privileged users) to perform Cross-Site Scripting attacks
- Affected:
- up to 2.16.4
- Fixed in:
- 2.16.4
Age Gate [age-gate] < 2.13.5
unknown
The plugin takes the _wp_http_referer parameter to redirect users after some actions as well as after invalid or missing nonces, leading to an Unauthenticated Open Redirect issue
- Affected:
- up to 2.13.5
- Fixed in:
- 2.13.5
Age Gate [age-gate] < 3.5.4
unknown
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4
CVE-2025-2505 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database