CRITICAL
9.8 CVE-2026-12227 Published 24 Sept 2026
Visual Composer WordPress Plugin Local File Inclusion Vulnerability
Worried this affects your website?
The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0.
This vulnerability exists via the vcv-template parameter, allowing unauthenticated attackers to include and execute arbitrary files on the server. This can lead to execution of any PHP code in those files.
Potential impacts include:
- Bypassing access controls
- Obtaining sensitive data
- Achieving code execution when images or other “safe” file types can be uploaded and included
Reference: CVE-2026-12227 on NVD
← Back to Security News