Description
Missing Authorization vulnerability in Phil Age Gate age-gate allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Age Gate: from n/a through <= 3.5.4.
Published: 2025-04-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Phil Age Gate WordPress plugin that allows users to access functions that are not properly restricted by access control lists. This flaw could enable an attacker to use any protected feature of the plugin without proper permission, potentially exposing sensitive data or altering site behavior. The weakness is an instance of CWE-862, a classic broken access control issue.

Affected Systems

The affected product is the Age Gate WordPress plugin from Phil, version 3.5.4 and earlier. Any WordPress installation using this plugin version is vulnerable. The original defect description indicates that all releases up to and including 3.5.4 are impacted; newer releases thereafter are assumed to be fixed.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate risk. The EPSS score of less than 1 percent suggests that exploitation is unlikely but not impossible; however the plugin is widely used by WordPress sites which may increase exposure. The vulnerability is not listed in the CISA KEV catalog. Because the flaw involves improper enforcement of ACLs, the most probable entry point is a WordPress user with access to the Age Gate plugin’s administrative functions; based on the description, it is inferred that an attacker with any authenticated WordPress role could try to call the restricted endpoints directly. No additional prerequisites such as system configuration are mentioned and the damage would be limited to the plugin’s scope, but it could allow unauthorized data retrieval or manipulation.

Generated by OpenCVE AI on May 1, 2026 at 10:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Age Gate plugin to the latest release (>= 3.5.5) to apply the vendor-fix.
  • After updating, verify that all administrative routes of the plugin enforce the expected role checks and that no endpoints remain publicly accessible.
  • Regularly review WordPress user roles and ensure that the least privileged principle is applied, restricting plugin management rights to trusted administrators.

Generated by OpenCVE AI on May 1, 2026 at 10:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10645 Missing Authorization vulnerability in Phil Age Gate allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Age Gate: from n/a through 3.5.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Phil Age Gate allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Age Gate: from n/a through 3.5.4. Missing Authorization vulnerability in Phil Age Gate age-gate allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Age Gate: from n/a through <= 3.5.4.
Title WordPress Age Gate <= 3.5.4 - Broken Access Control Vulnerability WordPress Age Gate plugin <= 3.5.4 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Phil Age Gate allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Age Gate: from n/a through 3.5.4.
Title WordPress Age Gate <= 3.5.4 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:03.648Z

Reserved: 2025-03-26T09:22:56.082Z

Link: CVE-2025-31012

cve-icon Vulnrichment

Updated: 2025-04-09T18:05:27.948Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:33.830

Modified: 2026-04-23T15:27:31.833

Link: CVE-2025-31012

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:00:15Z

Weaknesses