/Vulnerability Library

Visual Composer <= 45.16.0 - Unauthenticated LFI

CVE-2026-12227
Early Release

Description

Visual Composer Website Builder for WordPress <= 45.16.0 contains a local file inclusion vulnerability caused by improper validation of the vcv-template parameter, letting unauthenticated attackers include and execute arbitrary files, exploit requires no authentication.

Severity

Critical

CVSS Score

9.8

Affected Product

visualcomposer

Published Date

September 25, 2026

Template Author

0x_akoko

CVE-2026-12227.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-12227
CWE ID:
cwe-98

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualcomposer/visual-composer-website-builder-45160-unauthenticated-local-file-inclusion-via-vcv-template-parameterhttps://github.com/murrez/CVE-2026-12227https://nvd.nist.gov/vuln/detail/CVE-2026-12227

Remediation Steps

Update to the latest version beyond 45.16.0.