Skip to content
Critical LFI Vulnerability in Visual Composer Exposed

Critical LFI Vulnerability in Visual Composer Exposed

First seen 27 Sep 2026, 09:52 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 09:33 UTC
  • •CVE-2026-12227 is a critical LFI vulnerability in Visual Composer, CVSS 9.8.
  • •The flaw allows unauthenticated attackers to execute arbitrary files on the server.
  • •Active exploitation has been confirmed, with a PoC publicly available.

A critical unauthenticated Local File Inclusion (LFI) vulnerability, CVE-2026-12227, has been identified in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to 45.16.0. The flaw allows attackers to include and execute arbitrary files on the server through the vcv-template parameter, potentially leading to sensitive data exposure and Remote Code Execution (RCE) if the server is misconfigured. The vulnerability stems from a logic flaw in the PageTemplatesController.php file, where validation occurs before mutation, allowing crafted inputs to bypass security checks. The vulnerability was published on September 24, 2026, and a proof-of-concept (PoC) was made public on September 25, 2026. Users are urged to update to the latest version of the plugin to mitigate risks. The vulnerability has a CVSS score of 9.8, indicating its critical nature. Current exploitation status is confirmed as active, with reports of attacks in the wild. Security professionals are advised to assess their systems for affected versions and apply necessary patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-22
CVE-2026-87902 published
CVE-2026-87902 was published, affecting WordPress installations.
Sploitus
2026-09-24
CVE-2026-12227 published
CVE-2026-12227 was published, affecting Visual Composer versions up to 45.16.0.
Sploitus
2026-09-25
First public PoC for CVE-2026-12227
A proof-of-concept for CVE-2026-12227 was released, demonstrating the exploit.
Sploitus
2026-09-27
Active exploitation confirmed
Reports indicate that the CVE-2026-12227 vulnerability is being actively exploited in the wild.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2026-12227 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed