CRITICAL 9.8 CVE-2026-12227 Published 24 Sept 2026

Visual Composer WordPress Plugin Local File Inclusion Vulnerability

Worried this affects your website?

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0.

This vulnerability exists via the vcv-template parameter, allowing unauthenticated attackers to include and execute arbitrary files on the server. This can lead to execution of any PHP code in those files.

Potential impacts include:

  • Bypassing access controls
  • Obtaining sensitive data
  • Achieving code execution when images or other “safe” file types can be uploaded and included

Reference: CVE-2026-12227 on NVD

← Back to Security News