# CVE-2026-12227: Visual Composer Website Builder - LFI

> Live exploitation tracking for CVE-2026-12227 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-12227

## Key facts

- **Exploitation phase:** Insufficient Data. Not enough CrowdSec telemetry data is available to confidently assess how this vulnerability is exploited in the wild.
- **CVSS score:** 9.8
- **Public exploit available:** Yes
- **Affected products:** Visual Composer Website Builder
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** wordpress, cms

## Description

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

## CrowdSec analysis

[CVE-2026-12227](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-12227) is a critical local file inclusion vulnerability in the Visual Composer Website Builder plugin for WordPress versions up to and including 45.16.0. The flaw allows unauthenticated remote attackers to include and execute arbitrary files through the `vcv-template` parameter, potentially bypassing access controls, exposing sensitive information, and achieving remote code execution.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-12227 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target the WordPress root endpoint (`/?vcv-template-type=vc&vcv-template=...`) on sites running the Visual Composer plugin. Exploitation uses directory traversal in the `vcv-template` parameter to include sensitive local files such as `/etc/passwd`, potentially enabling unauthenticated file disclosure or PHP code execution.

## Timeline

- 2026-09-24: CVE Published. CVE-2026-12227 is published to NVD.
- 2026-10-05: Rule Released. CrowdSec releases a rule to detect CVE-2026-12227 exploitation attempts against the CrowdSec Network.

## References

- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-12227.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-12227) follows observed exploitation activity for CVE-2026-12227. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
