Age-Restriction WordPress Plugin Vulnerability Affects Users
CVE-2025-11855
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 11 November 2025
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2025-11855?
The Age-Restriction WordPress Plugin, up to version 3.0.2, contains a vulnerability in the 'age_restrictionRemoteSupportRequest' function that lacks proper authorization checks. This flaw allows any authenticated users, including those with subscriber roles, to create an admin user account using a hardcoded username and arbitrary password. This oversight poses significant security risks to WordPress sites using the plugin, enabling unauthorized access and administrative control.
Affected Version(s)
age-restriction 0 <= 3.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.