Current Age Plugin
Current Age Plugin has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Current Age Plugin has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nguyen Xuan Chien. Current Age Plugin is installed on roughly 70 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-58687Current Age Plugin <= 1.6 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
Current Age Plugin
Author
WP CMS Ninja
This plugin allows you to show current age using the shortcode [showcurrentage month=”1″ day=”1″ year=”2000″ template=”1″] in the content area and dynamically updates based on current date. Default template is number one if none is specified. Templates: Number 1: This template just outputs the number of years. Number 2: This template outputs the number of years with matching language. Number 3: This template outputs the number of months with matching language. Number 4: This template outputs the number of months and days with matching language. Number 5: This template outputs the number of weeks and days with matching language. Number 6: This template outputs the number of years, weeks and days with matching language. Number 7: This template outputs the number of months and weeks with matching language Number 8: This template outputs the number of days with matching language Number 9: This template outputs the number of years, months and days with matching language
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C