Age Verification for Checkout - WordPress Plugin Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Age Verification for Your Checkout Page WordPress plugin, specifically in version 1.20.0. The issue arises because the plugin dynamically generates web content without properly validating the source of potentially untrusted data, particularly in the 'myapp/class-wc-integration-agechecker-integration.php' file.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

The vulnerability can be reproduced by sending a request to the web application with unvalidated data that is processed by the Age Verification plugin. This can be done by manipulating the 'POST' data to include a script payload, which the application will reflect back without proper sanitization.

Remediation

Users can update to Age Verification for Your Checkout Page version 1.20.1, which addresses this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.7
remediation
7.7
relevance
0.0
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.