Skip to content

Known CVE

WordPress Age Gate <= 3.5.3 - Unauthenticated Local File Inclusion

The Age Gate plugin for WordPress up to version 3.5.3 contains a local PHP file inclusion caused by the 'lang' parameter, letting unauthenticated attackers include and execute arbitrary PHP files, exploit requires no authentication.

CVE-2025-2505

Critical2025CVSS 9.8CWE-98

cve2025 · wordpress · wp-plugin · age-gate · lfi · wp · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website