Age Gate - Path Traversal (CVE-2025-2505)
Description
The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
psychologyCrowdSec Analysis
CVE-2025-2505 is a critical local PHP file inclusion vulnerability in the Age Gate WordPress plugin through version 3.5.3, exploitable via the lang parameter. Unauthenticated remote attackers can include and execute arbitrary PHP files, potentially bypassing access controls, exposing sensitive information, or achieving remote code execution through uploaded files.
CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.
According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2025-2505 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2025-2505 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2025-2505 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.
Attackers target the WordPress REST route /?rest_route=/age-gate/v3/check, supplying the age_gate[lang] parameter with directory-traversal sequences such as ../../../../ to trigger unauthenticated local PHP file inclusion.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2025-03-20 |
| Rule Released | 2026-08-03 |
| CrowdSec First Seen | 2026-08-19 |