WPBakery Page Builder Pricing Tables WordPress Plugin Local File Inclusion Vulnerability

Vulnerability

A local file inclusion (LFI) vulnerability has been identified in the Pricing Tables for WPBakery Page Builder WordPress plugin, affecting versions prior to 3.0. The vulnerability arises because the plugin fails to properly validate certain shortcode attributes before using them to generate file paths for include functions. This oversight allows authenticated users, including subscribers, to exploit the vulnerability and perform LFI attacks.

Impact

Exploitation of this vulnerability allows for local file inclusion, where an attacker can read files on the server that they normally would not have access to.

Reproduction

To reproduce this vulnerability, an authenticated user with subscriber privileges can send a POST request to '/wp-admin/admin-ajax.php' with the 'action' parameter set to 'parse-media-shortcode' and the 'shortcode' parameter containing a crafted shortcode that includes a path traversal payload, such as '/../..//..//..//..//..//..//etc//passwd'. This request can be made using the browser's developer console.

Remediation

Users are advised to update the Pricing Tables for WPBakery Page Builder WordPress plugin to version 3.0 or later.

Added: Apr 7, 2026, 10:09 AM
Updated: Apr 7, 2026, 10:09 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
3.1
exploitability
6.8
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.