CVE-2025-14475: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14475 is a Local File Inclusion (LFI) vulnerability in the Extensive VC Addons for WPBakery Page Builder WordPress plugin, affecting all versions up to and including 1.9.1. The flaw allows unauthenticated attackers to include and execute arbitrary PHP files on the server via the shortcode_name parameter in the extensive_vc_init_shortcode_pagination AJAX action. It was published on December 13, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). The vulnerable function extensive_vc_get_module_template_part in lib/helpers-functions.php (line 78) accepts a user-supplied shortcode_name parameter through the extensive_vc_init_shortcode_pagination AJAX action without sufficient path normalization or validation, allowing directory traversal sequences to reach arbitrary PHP files on the server. Because the AJAX action is accessible without authentication, no privileges are required to trigger the inclusion. The vulnerable code paths are visible in the plugin's public Trac repository at shortcodes/shortcodes-functions.php lines 122 and 142 (Wordfence, Plugin Trac).

Impact

Successful exploitation allows an unauthenticated remote attacker to include and execute arbitrary PHP files already present on the server, resulting in full compromise of confidentiality, integrity, and availability of the affected WordPress installation. An attacker could read sensitive configuration files (e.g., wp-config.php), execute malicious PHP code to establish persistent backdoors or web shells, and potentially pivot to the underlying server infrastructure. The impact scope is limited to the affected server but could extend to hosted databases, stored credentials, and other co-located applications (Wordfence, Red Hat CVE).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, indicating a currently low probability of exploitation in the near term. The attack complexity is rated High (AC:H), which somewhat limits opportunistic exploitation despite requiring no authentication or user interaction.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Extensive VC Addons for WPBakery Page Builder plugin (version ≤ 1.9.1) using tools like WPScan, Shodan, or by checking the plugin's readme file at wp-content/plugins/extensive-vc-addon/readme.txt.
  2. Identify the vulnerable AJAX endpoint: The target endpoint is WordPress's standard AJAX handler at /wp-admin/admin-ajax.php, which is accessible without authentication for public AJAX actions.
  3. Craft the malicious request: Send an HTTP POST request to admin-ajax.php with the action parameter set to extensive_vc_init_shortcode_pagination and a crafted shortcode_name value containing path traversal sequences (e.g., ../../../../wp-config) to target a PHP file on the server.
  4. Trigger file inclusion: The server-side function extensive_vc_get_module_template_part processes the unsanitized shortcode_name and includes the targeted PHP file, executing any PHP code within it.
  5. Achieve code execution: If a previously uploaded file (e.g., via a separate file upload vulnerability or a writable directory) contains a PHP web shell, the attacker can execute arbitrary OS commands, establish persistence, or exfiltrate data (Wordfence, Plugin Trac).

Indicators of compromise

  • Network: Unusual POST requests to /wp-admin/admin-ajax.php with action=extensive_vc_init_shortcode_pagination and shortcode_name values containing ../ or encoded path traversal sequences (e.g., %2e%2e%2f).
  • Logs: WordPress or web server access logs showing repeated AJAX requests to admin-ajax.php with anomalous shortcode_name parameters from unexpected IP addresses or user agents.
  • File System: Presence of unexpected PHP files in writable directories (e.g., wp-content/uploads/) that could be targeted for inclusion; newly created or modified files in the plugin directory.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget, python) following AJAX requests to the vulnerable endpoint.

Mitigation and workarounds

Administrators should upgrade the Extensive VC Addons plugin to a version beyond 1.9.1 as soon as a patched release is available from the plugin author (nenad-obradovic). As an immediate interim measure, the plugin should be disabled until a patch is applied. Additional recommended actions include deploying Web Application Firewall (WAF) rules to block requests containing path traversal sequences in the shortcode_name parameter, auditing the WordPress installation for signs of compromise, and ensuring no writable directories contain PHP files that could be leveraged for code execution (Wordfence).

Community reactions

Wordfence published the vulnerability in their weekly WordPress vulnerability report for December 8–14, 2025, and it was picked up by automated security feeds including RedPacket Security and VulnDB (Wordfence Blog, RedPacket Security). The vulnerability was also referenced in a CISA vulnerability bulletin (SB25-349) and noted by ENISA's EUVD tracker. Community reaction has been limited, consistent with the absence of active exploitation or a public PoC.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93549HIGH8.8
  • cart-rest-api-for-woocommerce
NoYesOct 04, 2026
CVE-2026-78371MEDIUM5.9
  • woo-addon-uploads
NoYesOct 05, 2026
CVE-2026-13607MEDIUM5.9
  • woo-addon-uploads
NoNoOct 05, 2026
CVE-2026-84169MEDIUM5.3
  • upi-qr-code-payment-gateway
NoNoOct 05, 2026
CVE-2026-97332MEDIUM5.3
  • user-private-files
NoYesOct 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management