WordPress Plugin Vulnerability: Extensive VC Addons < 1.9.1 – RCE Alert!
Beware of the plugin apocalypse! Extensive VC Addons for WPBakery Page Builder versions below 1.9.1 are under attack. Unauthenticated remote code execution (RCE) is on the loose, making websites vulnerable to exploits. So, update that plugin faster than you can say “CVE-2023-0159” or risk turning your site into a hacker’s playground.

Hot Take:
Who knew that the WPBakery Page Builder was baking up a storm of vulnerabilities? It seems like the “Extensive VC Addons” were a little too extensive, letting hackers in for a free buffet of remote code execution. Someone call the kitchen police!
Key Points:
- There’s a nasty Remote Code Execution (RCE) vulnerability in Extensive VC Addons for WPBakery Page Builder versions below 1.9.1.
- The exploit is unauthenticated, meaning it doesn’t need a password or an invite to crash your website party.
- Tested on both Windows and Linux platforms, this vulnerability is as versatile as it is dangerous.
- The exploit, CVE-2023-0159, was discovered by a security researcher named Ravina.
- This vulnerability allows hackers to execute arbitrary commands or access sensitive files on affected servers.
Already a member? Log in here