Visual Composer Website Builder - LFI (CVE-2026-12227)
Description
The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the vcv-template parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
psychologyCrowdSec Analysis
CVE-2026-12227 is a critical local file inclusion vulnerability in the Visual Composer Website Builder plugin for WordPress versions up to and including 45.16.0. The flaw allows unauthenticated remote attackers to include and execute arbitrary files through the vcv-template parameter, potentially bypassing access controls, exposing sensitive information, and achieving remote code execution.
CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2026-12227 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Attackers target the WordPress root endpoint (/?vcv-template-type=vc&vcv-template=...) on sites running the Visual Composer plugin. Exploitation uses directory traversal in the vcv-template parameter to include sensitive local files such as /etc/passwd, potentially enabling unauthenticated file disclosure or PHP code execution.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-09-24 |
| Rule Released | 2026-10-05 |