PHP Remote File Inclusion Vulnerability in Extensive VC Addons for WPBakery Page Builder
CVE-2025-60087
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 February 2026
What is CVE-2025-60087?
The Extensive VC Addons for WPBakery page builder suffers from a PHP Remote File Inclusion vulnerability that permits attackers to manipulate file includes. This flaw allows unauthorized access to local files on the server, potentially leading to compromised site integrity and data exposure. The issue is present in versions of the plugin from n/a to version 1.9.1. It is crucial for users to evaluate their installations and apply necessary security measures to mitigate risks.
Affected Version(s)
Extensive VC Addons for WPBakery page builder 0 <= 1.9.1