Description
Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through 3.0.
Published: 2026-01-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect privilege assignment flaw in AA‑Team Premium Age Verification / Restriction for WordPress and AA‑Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows an attacker to elevate their access level beyond what the plugin is intended to permit. By exploiting this weakness, an attacker could gain higher‑privileged permissions within the WordPress installation, enabling the execution of actions usually reserved for administrators. The flaw falls under CWE‑266, which highlights improper authorization controls and can compromise the integrity of the system.

Affected Systems

The vulnerability affects AA‑Team Premium Age Verification / Restriction for WordPress up through version 3.0.2 and AA‑Team Responsive Coming Soon Landing Page / Holding Page for WordPress up through version 3.0. No earlier launch date is specified. Users running these plugins on any WordPress site are potentially impacted unless they have upgraded to a fixed release.

Risk and Exploitability

With a CVSS score of 8.8 the flaw is classified as High. The EPSS score is less than 1%, indicating a low exploitation probability, and it is not listed in the CISA KEV catalog. The likely attack vector is remote: a non‑privileged user or a script can send a crafted request to the vulnerable plugin’s endpoints, triggering the privilege escalation. Although exploitation is considered improbable, the severity of the impact warrants prompt action.

Generated by OpenCVE AI on April 30, 2026 at 14:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update AA‑Team Premium Age Verification / Restriction to the latest patch version (3.0.3 or later).
  • Update AA‑Team Responsive Coming Soon Landing Page / Holding Page to the latest patch for the plugin (v3.1 or later).
  • If no patch is available, temporarily disable the affected plugins until a fix is released.
  • Verify that no unintended role elevations exist by reviewing user role assignments in the WordPress admin.

Generated by OpenCVE AI on April 30, 2026 at 14:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 19:30:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress wordpress-flat-countdown allows Privilege Escalation.This issue affects Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through <= 3.0. Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through 3.0.
Title WordPress Responsive Coming Soon Landing Page / Holding Page for WordPress plugin <= 3.0 - Privilege Escalation Vulnerability Privilege Escalation Vulnerability in AA-Team WordPress plugins
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through 3.0. Incorrect Privilege Assignment vulnerability in AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress wordpress-flat-countdown allows Privilege Escalation.This issue affects Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through <= 3.0.
Title Privilege Escalation Vulnerability in AA-Team WordPress plugins WordPress Responsive Coming Soon Landing Page / Holding Page for WordPress plugin <= 3.0 - Privilege Escalation Vulnerability
References

Wed, 07 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Aa-team
Aa-team premium Age Verification Restriction For Wordpress
Aa-team responsive Coming Soon Landing Page Holding Page For Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Aa-team
Aa-team premium Age Verification Restriction For Wordpress
Aa-team responsive Coming Soon Landing Page Holding Page For Wordpress
Wordpress
Wordpress wordpress

Tue, 06 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 20:45:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through 3.0.
Title Privilege Escalation Vulnerability in AA-Team WordPress plugins
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Aa-team Premium Age Verification Restriction For Wordpress Responsive Coming Soon Landing Page Holding Page For Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:52.852Z

Reserved: 2025-03-11T08:10:52.911Z

Link: CVE-2025-29004

cve-icon Vulnrichment

Updated: 2026-01-06T20:56:55.520Z

cve-icon NVD

Status : Deferred

Published: 2026-01-06T21:15:42.240

Modified: 2026-04-28T19:30:13.560

Link: CVE-2025-29004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T14:30:06Z

Weaknesses