Visual Composer <= 45.16.0 - Unauthenticated LFI
CVE-2026-12227
Early Release
Description
Visual Composer Website Builder for WordPress <= 45.16.0 contains a local file inclusion vulnerability caused by improper validation of the vcv-template parameter, letting unauthenticated attackers include and execute arbitrary files, exploit requires no authentication.
Severity
Critical
CVSS Score
9.8
Affected Product
visualcomposer
Published Date
September 25, 2026
Template Author
0x_akoko
CVE-2026-12227.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-12227
CWE ID:
cwe-98
Remediation Steps
Update to the latest version beyond 45.16.0.