CVE-2025-11855
Age Restriction <= 3.0.2 - Subscriber+ Privilege Escalation
CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
23th
The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password.
| Vendor | unknown |
| Product | age-restriction |
| Published | Nov 11, 2025 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown age-restriction
Be the first to know when new high vulnerabilities affecting unknown age-restriction are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / age-restriction
0 โค 3.0.2
References
Credits
Khaled Alenazi (Nxploited) WPScan