plugin

Age Gate Vulnerabilities

17 known security issues reported for the Age Gate WordPress plugin. Most recent disclosed Apr 9, 2025.

1 critical 1 high 3 medium

Running Age Gate on your site? Check whether your installed version is affected.

Scan your site free

Age Gate <= 3.5.4 - Missing Authorization

medium

The Age Gate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the store() function in all versions up to, and including, 3.5.4. This makes it possible for unauthenticated attackers to update settings.

CVSS:
5.3
Affected:
up to 3.5.4
Fixed in:
3.6.0
Disclosed:
Apr 9, 2025

CVE-2025-31012 on NVD →

Age Gate [age-gate] < 3.6.0

unknown

[en] Missing Authorization vulnerability in Phil Age Gate allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Age Gate: from n/a through 3.5.4.

Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Apr 9, 2025

CVE-2025-31012 on NVD →

Age Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang'

critical

The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be used...

CVSS:
9.8
Affected:
up to 3.5.3
Fixed in:
3.5.4
Disclosed:
Mar 19, 2025

CVE-2025-2505 on NVD →

Age Gate <= 2.13.4 - Open Redirect

medium

The Age Gate plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 2.13.4 via the '_wp_http_referer' parameter. This makes it possible for unauthenticated attackers to send users redirection links to hostile sites by using the website's address.

CVSS:
4.7
Affected:
up to 2.13.5
Fixed in:
2.13.5
Disclosed:
Nov 27, 2022

Age Gate [age-gate] < 2.13.5

unknown

The Age Gate plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 2.13.4 via the '_wp_http_referer' parameter. This makes it possible for unauthenticated attackers to send users redirection links to hostile sites by using the website's address.

Affected:
up to 2.13.5
Fixed in:
2.13.5
Disclosed:
Nov 27, 2022

Age Gate [age-gate] < 2.17.1

unknown

[en] Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Phil Baker's Age Gate plugin <= 2.17.0 at WordPress.

Affected:
up to 2.17.1
Fixed in:
2.17.1
Disclosed:
Jun 15, 2022

CVE-2021-36901 on NVD →

Age Gate <= 2.17.0 - Cross-Site Scripting via Data Import

high

The Age Gate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data imports in versions up to, and including, 2.17.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...

CVSS:
7.2
Affected:
up to 2.17.0
Fixed in:
2.17.1
Disclosed:
Jun 10, 2022

CVE-2021-36901 on NVD →

Age Gate [age-gate] < 2.17.1

unknown

Unauthenticated Import Settings vulnerability discovered in WordPress Age Gate (versions <= 2.17.0).

Affected:
up to 2.17.1
Fixed in:
2.17.1
Disclosed:
Oct 25, 2021

Age Gate <= 2.16.3 - Stored Cross-Site Scripting

medium

The Age Gate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Additional content’ field in versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will ex...

CVSS:
6.4
Affected:
up to 2.16.4
Fixed in:
2.16.4
Disclosed:
Oct 6, 2021

Age Gate [age-gate] < 2.16.4

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Martin Vierula (Trustwave) in WordPress Age Gate plugin (versions <= 2.16.3).

Affected:
up to 2.16.4
Fixed in:
2.16.4
Disclosed:
Oct 6, 2021

Age Gate [age-gate] < 2.16.4

unknown

The Age Gate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Additional content’ field in versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will ex...

Affected:
up to 2.16.4
Fixed in:
2.16.4
Disclosed:
Oct 6, 2021

Age Gate [age-gate] < 2.13.5

unknown

URL Redirection to Untrusted Site ('Open Redirect') vulnerability found by Ilca Lucian Florin in WordPress WordPress Age Gate plugin (versions <= 2.13.4).

Affected:
up to 2.13.5
Fixed in:
2.13.5
Disclosed:
Nov 30, 2020

Age Gate [age-gate] < 2.20.4

unknown

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 2.20.4
Fixed in:
2.20.4

Age Gate [age-gate] < 2.17.1

unknown

The plugin patched an Unauthenticated Import Settings vulnerability. It was found to be exploited in the wild a few days after being patched.

Affected:
up to 2.17.1
Fixed in:
2.17.1

Age Gate [age-gate] < 2.16.4

unknown

The plugin does not sanitise and escape the &#039;Additional content&#039; setting of its &#039;Messaging&#039; page, which could allow users having access to such setting (by default admin, but the plugin has a feature to change this and allow access to lower privileged users) to perform Cross-Site Scripting attacks

Affected:
up to 2.16.4
Fixed in:
2.16.4

Age Gate [age-gate] < 2.13.5

unknown

The plugin takes the _wp_http_referer parameter to redirect users after some actions as well as after invalid or missing nonces, leading to an Unauthenticated Open Redirect issue

Affected:
up to 2.13.5
Fixed in:
2.13.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database