Vulnerability CVE-2023-0159


Published: 2023-02-13

Description:
The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system.

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

 References:
https://wpscan.com/vulnerability/239ea870-66e5-4754-952e-74d4dd60b809

Copyright 2026, cxsecurity.com

 

Back to Top