Impact
The Age Gate plugin for WordPress contains a flaw that allows an unauthenticated attacker to include and execute arbitrary PHP files through the 'lang' parameter. This vulnerability falls under CWE‑22 and can be used to bypass access controls and exfiltrate sensitive data, or to achieve code execution when the attacker can place files such as images in upload directories that are later included.
Affected Systems
WordPress sites running the philsbury Age Gate plugin, versions up to and including 3.5.3 are affected. Any installation of these vulnerable plugin versions is at risk.
Risk and Exploitability
The CVSS score of 9.8 combined with an EPSS score of 2% indicates a high likelihood that this vulnerability may be actively exploited. Although it is not listed in the CISA KEV catalog, the public disclosure and available references suggest that attackers can trigger the flaw remotely via HTTP requests that supply a path to a local PHP file, possibly through uploaded “safe” file types that are later included.
OpenCVE Enrichment
EUVD