
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-29004 is an Incorrect Privilege Assignment vulnerability (CWE-266) affecting two WordPress plugins developed by AA-Team: Premium Age Verification / Restriction for WordPress (versions through 3.0.2) and Responsive Coming Soon Landing Page / Holding Page for WordPress (versions through 3.0). The vulnerability allows authenticated attackers with low-level privileges to escalate their privileges to administrative levels. It was disclosed on January 6, 2026, by Patchstack, which serves as the CVE Numbering Authority (CNA) for this entry. The CVSS v3.1 base score is 8.8 (High) (Patchstack).
The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the affected plugins incorrectly assign or fail to properly validate privilege levels during certain operations, allowing a lower-privileged authenticated user to gain higher-level capabilities. The attack vector is network-based, requires low privileges (e.g., a subscriber or contributor account), and demands no user interaction, making it straightforward to exploit once an attacker has any valid WordPress account. The flaw exists in both the age-restriction and wordpress-flat-countdown plugin codebases up to their respective version thresholds. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an authenticated attacker with minimal privileges (e.g., a subscriber-level account) to escalate to administrator-level access on the affected WordPress installation. This can result in full compromise of the WordPress site, including unauthorized reading of sensitive data, modification of site content and configurations, deletion of data, installation of backdoors or malicious plugins, and potential lateral movement to the underlying server infrastructure. The confidentiality, integrity, and availability impacts are all rated High (Patchstack).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.039%, indicating a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Patchstack).
wp-login.php or REST API logs from low-privilege accounts accessing admin endpoints.wp-config.php or core WordPress files; presence of web shells in the uploads or plugin directories.wp_usermeta or wp_users tables, particularly wp_capabilities fields showing escalated roles for previously low-privilege accounts./wp-admin/admin-ajax.php) or REST API routes from authenticated low-privilege sessions.Administrators should immediately disable or uninstall the affected plugins — Premium Age Verification / Restriction for WordPress (versions ≤ 3.0.2) and Responsive Coming Soon Landing Page / Holding Page for WordPress (versions ≤ 3.0) — until patched versions are confirmed available. Restrict WordPress user registration to trusted individuals and audit existing user accounts for unauthorized privilege changes. Implement a Web Application Firewall (WAF) with WordPress-specific rulesets to detect and block exploitation attempts. Regularly review WordPress user roles and capabilities, and monitor audit logs for anomalous privilege assignments (Patchstack).
The vulnerability was reported by Patchstack, a WordPress security firm that serves as the CNA for this CVE. Coverage has been limited to vulnerability aggregation platforms and security news digests, including a CISA weekly vulnerability bulletin (SB26-012) and IT security news summaries for the week of January 5, 2026. No notable independent researcher commentary or significant social media discussion has been identified beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."