Junglewise Threat Intelligence

CVE-2025-49403: AA-Team Premium Age Verification / Restriction arbitrary file download

CVE-2025-49403 · Severity: high · CVSS 7.5 · Published 2026-06-17

Executive brief

A vulnerability in the Premium Age Verification / Restriction plugin for WordPress allows unauthorized individuals to download sensitive files from the web server. This plugin is typically used to restrict access to age-sensitive content; however, this flaw could lead to the exposure of configuration files, database credentials, or other private data. An attacker could use this information to gain further access to the website or its underlying infrastructure.

Technical details

The Premium Age Verification / Restriction plugin for WordPress is vulnerable to an unauthenticated arbitrary file download due to improper control of filenames (CWE-98/CWE-22). An attacker can exploit this by sending a specially crafted request to the server, allowing them to read and download sensitive files from the local file system that the web server process has access to. This includes critical files like wp-config.php, which contains database credentials. As of the advisory date, no official patch has been released, though third-party mitigation rules are available.

Affected products

  • AA-Team Premium Age Verification / Restriction for WordPress <= 3.0.2

Timeline

  • 2025-06-27: other: Vulnerability reported by researcher ch4r0n
  • 2025-08-26: advisory: Initial advisory published by Patchstack
  • 2026-06-17: disclosed: NVD publication date

References