# CVE-2025-2505: Age Gate - Path Traversal

> Live exploitation tracking for CVE-2025-2505 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2025-2505

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 9.8
- **Public exploit available:** Yes
- **Affected products:** Philsbury Age Gate
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** wordpress, cms

## Description

The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

## CrowdSec analysis

[CVE-2025-2505](https://euvd.enisa.europa.eu/vulnerability/CVE-2025-2505) is a critical local PHP file inclusion vulnerability in the Age Gate WordPress plugin through version 3.5.3, exploitable via the `lang` parameter. Unauthenticated remote attackers can include and execute arbitrary PHP files, potentially bypassing access controls, exposing sensitive information, or achieving remote code execution through uploaded files.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2025-2505 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2025-2505 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2025-2505 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.

Attackers target the WordPress REST route `/?rest_route=/age-gate/v3/check`, supplying the `age_gate[lang]` parameter with directory-traversal sequences such as `../../../../` to trigger unauthenticated local PHP file inclusion.

## Timeline

- 2025-03-20: CVE Published. CVE-2025-2505 is published to NVD.
- 2026-08-03: Rule Released. CrowdSec releases a rule to detect CVE-2025-2505 exploitation attempts against the CrowdSec Network.
- 2026-08-19: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2025-2505 for the first time.

## References

- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-2505.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2025-2505) follows observed exploitation activity for CVE-2025-2505. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
