CVE-2025-11855
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-13
Assigner: WPScan
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpress | age_restriction | 3.0.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the age-restriction WordPress plugin through version 3.0.2. It lacks proper authorization in the age_restrictionRemoteSupportRequest function, which allows any authenticated user, including low-privileged users like subscribers, to create an admin user with a hardcoded username and an arbitrary password.
How can this vulnerability impact me? :
An attacker who is an authenticated user on the WordPress site can exploit this vulnerability to create a new admin user account. This grants them full administrative access to the site, allowing them to control site content, settings, and potentially compromise the entire website.