๐Ÿ” CVE Alert

CVE-2025-11855

HIGH 7.5

Age Restriction <= 3.0.2 - Subscriber+ Privilege Escalation

CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
23th

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password.

Vendor unknown
Product age-restriction
Published Nov 11, 2025
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown age-restriction

Be the first to know when new high vulnerabilities affecting unknown age-restriction are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / age-restriction
0 โ‰ค 3.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1a16440e-817f-4ec2-9c70-261f6b63fb8a/

Credits

Khaled Alenazi (Nxploited) WPScan