
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14475 is a Local File Inclusion (LFI) vulnerability in the Extensive VC Addons for WPBakery Page Builder WordPress plugin, affecting all versions up to and including 1.9.1. The flaw allows unauthenticated attackers to include and execute arbitrary PHP files on the server via the shortcode_name parameter in the extensive_vc_init_shortcode_pagination AJAX action. It was published on December 13, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). The vulnerable function extensive_vc_get_module_template_part in lib/helpers-functions.php (line 78) accepts a user-supplied shortcode_name parameter through the extensive_vc_init_shortcode_pagination AJAX action without sufficient path normalization or validation, allowing directory traversal sequences to reach arbitrary PHP files on the server. Because the AJAX action is accessible without authentication, no privileges are required to trigger the inclusion. The vulnerable code paths are visible in the plugin's public Trac repository at shortcodes/shortcodes-functions.php lines 122 and 142 (Wordfence, Plugin Trac).
Successful exploitation allows an unauthenticated remote attacker to include and execute arbitrary PHP files already present on the server, resulting in full compromise of confidentiality, integrity, and availability of the affected WordPress installation. An attacker could read sensitive configuration files (e.g., wp-config.php), execute malicious PHP code to establish persistent backdoors or web shells, and potentially pivot to the underlying server infrastructure. The impact scope is limited to the affected server but could extend to hosted databases, stored credentials, and other co-located applications (Wordfence, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, indicating a currently low probability of exploitation in the near term. The attack complexity is rated High (AC:H), which somewhat limits opportunistic exploitation despite requiring no authentication or user interaction.
wp-content/plugins/extensive-vc-addon/readme.txt./wp-admin/admin-ajax.php, which is accessible without authentication for public AJAX actions.admin-ajax.php with the action parameter set to extensive_vc_init_shortcode_pagination and a crafted shortcode_name value containing path traversal sequences (e.g., ../../../../wp-config) to target a PHP file on the server.extensive_vc_get_module_template_part processes the unsanitized shortcode_name and includes the targeted PHP file, executing any PHP code within it./wp-admin/admin-ajax.php with action=extensive_vc_init_shortcode_pagination and shortcode_name values containing ../ or encoded path traversal sequences (e.g., %2e%2e%2f).admin-ajax.php with anomalous shortcode_name parameters from unexpected IP addresses or user agents.wp-content/uploads/) that could be targeted for inclusion; newly created or modified files in the plugin directory.bash, curl, wget, python) following AJAX requests to the vulnerable endpoint.Administrators should upgrade the Extensive VC Addons plugin to a version beyond 1.9.1 as soon as a patched release is available from the plugin author (nenad-obradovic). As an immediate interim measure, the plugin should be disabled until a patch is applied. Additional recommended actions include deploying Web Application Firewall (WAF) rules to block requests containing path traversal sequences in the shortcode_name parameter, auditing the WordPress installation for signs of compromise, and ensuring no writable directories contain PHP files that could be leveraged for code execution (Wordfence).
Wordfence published the vulnerability in their weekly WordPress vulnerability report for December 8–14, 2025, and it was picked up by automated security feeds including RedPacket Security and VulnDB (Wordfence Blog, RedPacket Security). The vulnerability was also referenced in a CISA vulnerability bulletin (SB25-349) and noted by ENISA's EUVD tracker. Community reaction has been limited, consistent with the absence of active exploitation or a public PoC.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."