Extensive VC Addons for WPBakery page builder [extensive-vc-addon] <= 1.9.1 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC Addons for WPBakery page builder extensive-vc-addon allows PHP Local File Inclusion.This issue affects Extensive VC Addons for WPBakery page builder: from n/a throug...
- Affected:
- up to 1.9.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-60087 on NVD →
Extensive VC Addons for WPBakery page builder [extensive-vc-addon] <= 1.9.1 (unfixed)
unknown
[en] The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.1 via the `extensive_vc_get_module_template_part` function. This is due to insufficient path normalization and validation of the user-supplied `shortcode_name` para...
- Affected:
- up to 1.9.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 13, 2025
CVE-2025-14475 on NVD →
Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion via 'shortcode_name' Parameter
high
The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.1 via the `extensive_vc_get_module_template_part` function. This is due to insufficient path normalization and validation of the user-supplied `shortcode_name` parameter...
- CVSS:
- 8.1
- Affected:
- up to 1.9.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 12, 2025
CVE-2025-14475 on NVD →
Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion
high
The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can...
- CVSS:
- 8.1
- Affected:
- up to 1.9.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2025
CVE-2025-60087 on NVD →
Extensive VC Addons for WPBakery page builder [extensive-vc-addon] < 1.9.1
unknown
[en] The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RC...
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.1
- Disclosed:
- Feb 13, 2023
CVE-2023-0159 on NVD →
Extensive VC Addons for WPBakery page builder <= 1.9 - Unauthenticated Local File Inclusion
critical
The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9 via the extensive_vc_get_module_template_part function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of...
- CVSS:
- 9.1
- Affected:
- up to 1.9
- Fixed in:
- 1.9.1
- Disclosed:
- Jan 23, 2023
CVE-2023-0159 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database