Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-11855

Опубликовано: 11 нояб. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password.

EPSS

Процентиль: 16%
0.0005
Низкий

7.5 High

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 7.3
github
3 месяца назад

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password.

EPSS

Процентиль: 16%
0.0005
Низкий

7.5 High

CVSS3

Дефекты