CVE-2025-29004
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-29004 is an Incorrect Privilege Assignment vulnerability (CWE-266) affecting two WordPress plugins developed by AA-Team: Premium Age Verification / Restriction for WordPress (versions through 3.0.2) and Responsive Coming Soon Landing Page / Holding Page for WordPress (versions through 3.0). The vulnerability allows authenticated attackers with low-level privileges to escalate their privileges to administrative levels. It was disclosed on January 6, 2026, by Patchstack, which serves as the CVE Numbering Authority (CNA) for this entry. The CVSS v3.1 base score is 8.8 (High) (Patchstack).

Technical details

The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the affected plugins incorrectly assign or fail to properly validate privilege levels during certain operations, allowing a lower-privileged authenticated user to gain higher-level capabilities. The attack vector is network-based, requires low privileges (e.g., a subscriber or contributor account), and demands no user interaction, making it straightforward to exploit once an attacker has any valid WordPress account. The flaw exists in both the age-restriction and wordpress-flat-countdown plugin codebases up to their respective version thresholds. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an authenticated attacker with minimal privileges (e.g., a subscriber-level account) to escalate to administrator-level access on the affected WordPress installation. This can result in full compromise of the WordPress site, including unauthorized reading of sensitive data, modification of site content and configurations, deletion of data, installation of backdoors or malicious plugins, and potential lateral movement to the underlying server infrastructure. The confidentiality, integrity, and availability impacts are all rated High (Patchstack).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.039%, indicating a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Premium Age Verification / Restriction" plugin (version ≤ 3.0.2) or "Responsive Coming Soon Landing Page / Holding Page" plugin (version ≤ 3.0) using tools like WPScan or by inspecting plugin directories.
  2. Obtain low-privilege account: Register or obtain credentials for a low-privilege WordPress account (e.g., subscriber or contributor role) on the target site.
  3. Trigger privilege escalation: Interact with the vulnerable plugin functionality that incorrectly assigns privileges — this may involve sending crafted requests to plugin-specific endpoints or admin-ajax handlers that fail to enforce proper capability checks.
  4. Achieve elevated access: Upon successful exploitation, the attacker's account is granted administrator-level privileges, enabling full control of the WordPress dashboard, including plugin/theme installation, user management, and file system access.

Indicators of compromise

  • Logs: WordPress authentication logs showing a low-privilege user account (subscriber/contributor) suddenly performing administrator-level actions; unexpected entries in wp-login.php or REST API logs from low-privilege accounts accessing admin endpoints.
  • File System: Newly installed plugins or themes not authorized by site administrators; modified wp-config.php or core WordPress files; presence of web shells in the uploads or plugin directories.
  • WordPress Database: Unexpected changes to the wp_usermeta or wp_users tables, particularly wp_capabilities fields showing escalated roles for previously low-privilege accounts.
  • Network: Unusual POST requests to WordPress admin-ajax endpoints (/wp-admin/admin-ajax.php) or REST API routes from authenticated low-privilege sessions.

Mitigation and workarounds

Administrators should immediately disable or uninstall the affected plugins — Premium Age Verification / Restriction for WordPress (versions ≤ 3.0.2) and Responsive Coming Soon Landing Page / Holding Page for WordPress (versions ≤ 3.0) — until patched versions are confirmed available. Restrict WordPress user registration to trusted individuals and audit existing user accounts for unauthorized privilege changes. Implement a Web Application Firewall (WAF) with WordPress-specific rulesets to detect and block exploitation attempts. Regularly review WordPress user roles and capabilities, and monitor audit logs for anomalous privilege assignments (Patchstack).

Community reactions

The vulnerability was reported by Patchstack, a WordPress security firm that serves as the CNA for this CVE. Coverage has been limited to vulnerability aggregation platforms and security news digests, including a CISA weekly vulnerability bulletin (SB26-012) and IT security news summaries for the week of January 5, 2026. No notable independent researcher commentary or significant social media discussion has been identified beyond routine vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management