S4E just found a critical-severity finding from ruijie rg-uac remote code execution scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2012-6499 Scanner

CVE-2012-6499 scanner - Open Redirect vulnerability in Age Verification plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2012-6499
5.8
CVSS

Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Age Verification plugin for WordPress is a tool that enables website owners to restrict access to certain content or functionalities based on age.When users access a website, they are prompted to enter their date of birth to verify their eligibility to view the content or use the functionality. The Age Verification plugin is especially useful for websites that have legal age requirements, such as alcohol or tobacco retailers.

One vulnerability that was detected in the Age Verification plugin is the CVE-2012-6499. This vulnerability allows remote attackers to redirect users to arbitrary websites via a URL in the redirect_to parameter. Essentially, a malicious actor could create a URL that seems legitimate but, when clicked, would redirect the user to a phishing site or other malicious destination. 

If this vulnerability is exploited, it can lead to several negative consequences for website owners and users. For website owners, it can potentially damage their reputation if their users fall prey to phishing scams or other malicious attacks. For users, it can lead to identity theft or financial loss if they unwittingly provide sensitive information to criminals. In addition, any website that has legal age requirements could face legal consequences if underage individuals gain access to restricted content.

Overall, the Age Verification plugin is a useful tool for website owners who need to restrict access based on age requirements. However, it is important to be aware of potential vulnerabilities, such as the CVE-2012-6499, and take appropriate precautions to protect against them. With the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets and take steps to mitigate them.

 

REEFERENCES

Solution Advice

Fortunately, there are several precautions website owners can take to protect against this vulnerability. These include:

  • Keeping the Age Verification plugin up to date with the latest version
  • Limiting the use of the redirect_to parameter
  • Ensuring that the plugin code is secure
  • Using a security plugin or service to monitor for vulnerabilities and attacks
  • Educating users about the risks of clicking on suspicious links or providing personal information

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2012-6499 scanner - Open Redirect vulnerability in Age Verification plugin for WordPress | S4E