CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2025-2505Public Exploit

Age Gate - Path Traversal (CVE-2025-2505)

PublishedMar 20, 2025
First SeenAug 19, 2026
Last Seen
Reported
CVSS9.8
wordpresscms

Description

The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

psychologyCrowdSec Analysis

CVE-2025-2505 is a critical local PHP file inclusion vulnerability in the Age Gate WordPress plugin through version 3.5.3, exploitable via the lang parameter. Unauthenticated remote attackers can include and execute arbitrary PHP files, potentially bypassing access controls, exposing sensitive information, or achieving remote code execution through uploaded files.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2025-2505 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2025-2505 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2025-2505 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.

Attackers target the WordPress REST route /?rest_route=/age-gate/v3/check, supplying the age_gate[lang] parameter with directory-traversal sequences such as ../../../../ to trigger unauthenticated local PHP file inclusion.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2025-03-20
Rule Released2026-08-03
CrowdSec First Seen2026-08-19

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.