Age Restriction <= 3.0.2 - Authenticated (Subscriber+) Privilege Escalation
high
The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the 'age_restrictionRemoteSupportRequest' AJAX action in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with Subscriber-...
- CVSS:
- 8.8
- Affected:
- up to 3.0.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 21, 2025
CVE-2025-11855 on NVD →
Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Download
high
The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 3.0.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 26, 2025
CVE-2025-49403 on NVD →
Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write via remote_tunnel.php
critical
The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attac...
- CVSS:
- 9.8
- Affected:
- up to 3.0.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 10, 2025
CVE-2025-7401 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database