Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

Nenad Obradovic WPBakery Addons Exposes Local Files

CVE-2025-60087
Summary

A security flaw in Nenad Obradovic's Extensive VC Addons for WPBakery page builder allows hackers to access and read local files on the server. This affects versions up to 1.9.1, but the latest version is available. Update to the latest version to fix the issue.

Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC Addons for WPBakery page builder extensive-vc-a...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC Addons for WPBakery page builder extensive-vc-addon allows PHP Local File Inclusion.This issue affects Extensive VC Addons for WPBakery page builder: from n/a through <= 1.9.1.
nvd CVSS3.1 8.1
Vulnerability type
CWE-98 Improper Control of Filename for Include
Published: 20 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026