plugin

Extensive Vc Addon Vulnerabilities

6 known security issues reported for the Extensive Vc Addon WordPress plugin. Most recent disclosed Feb 20, 2026.

1 critical 2 high

Running Extensive Vc Addon on your site? Check whether your installed version is affected.

Scan your site free

Extensive VC Addons for WPBakery page builder [extensive-vc-addon] <= 1.9.1 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC Addons for WPBakery page builder extensive-vc-addon allows PHP Local File Inclusion.This issue affects Extensive VC Addons for WPBakery page builder: from n/a throug...

Affected:
up to 1.9.1
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-60087 on NVD →

Extensive VC Addons for WPBakery page builder [extensive-vc-addon] <= 1.9.1 (unfixed)

unknown

[en] The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.1 via the `extensive_vc_get_module_template_part` function. This is due to insufficient path normalization and validation of the user-supplied `shortcode_name` para...

Affected:
up to 1.9.1
Fix:
No patched version reported
Disclosed:
Dec 13, 2025

CVE-2025-14475 on NVD →

Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion via 'shortcode_name' Parameter

high

The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.1 via the `extensive_vc_get_module_template_part` function. This is due to insufficient path normalization and validation of the user-supplied `shortcode_name` parameter...

CVSS:
8.1
Affected:
up to 1.9.1
Fix:
No patched version reported
Disclosed:
Dec 12, 2025

CVE-2025-14475 on NVD →

Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion

high

The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can...

CVSS:
8.1
Affected:
up to 1.9.1
Fix:
No patched version reported
Disclosed:
Aug 15, 2025

CVE-2025-60087 on NVD →

Extensive VC Addons for WPBakery page builder [extensive-vc-addon] < 1.9.1

unknown

[en] The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RC...

Affected:
up to 1.9.1
Fixed in:
1.9.1
Disclosed:
Feb 13, 2023

CVE-2023-0159 on NVD →

Extensive VC Addons for WPBakery page builder <= 1.9 - Unauthenticated Local File Inclusion

critical

The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9 via the extensive_vc_get_module_template_part function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of...

CVSS:
9.1
Affected:
up to 1.9
Fixed in:
1.9.1
Disclosed:
Jan 23, 2023

CVE-2023-0159 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database