PT-2025-51077 · Unknown+1 · Wpbakery Page Builder+1

Naoya Takahashi

·

Published

2025-12-13

·

Updated

2025-12-18

·

CVE-2025-14475

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Extensive VC Addons for WPBakery page builder plugin for WordPress versions prior to 1.9.2
Description The software is susceptible to a Local File Inclusion issue due to insufficient path normalization and validation of the shortcode name parameter within the extensive vc init shortcode pagination AJAX action and the extensive vc get module template part function. This allows unauthenticated attackers to include and execute arbitrary PHP files on the server, potentially enabling the execution of any PHP code within those files.
Recommendations Update Extensive VC Addons for WPBakery page builder plugin for WordPress to version 1.9.2 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-14475

Affected Products

Extensive Vc Addons For Wpbakery Page Builder
Wpbakery Page Builder