7.5
CVSSv3

CVE-2023-0159

Published: 13/02/2023 Updated: 05/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Extensive VC Addons for WPBakery page builder WordPress plugin prior to 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated malicious user to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.

Vulnerable Product Search on Vulmon Subscribe to Product

wprealize extensive vc addons for wpbakery page builder

Github Repositories

Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI

EVCer | CVE-2023-0159 - Extensive VC Addons for WPBakery page builder Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder &lt; 191 - Unauthenticated LFIUsing GNU Parallel You must have parallel for running this tool If you found error like "$'\r': command not found" just do "dos2unix e