Sploitus Critical LFI Vulnerability in Visual Composer Exposed
Article Content
- •CVE-2026-12227 is a critical LFI vulnerability in Visual Composer, CVSS 9.8.
- •The flaw allows unauthenticated attackers to execute arbitrary files on the server.
- •Active exploitation has been confirmed, with a PoC publicly available.
A critical unauthenticated Local File Inclusion (LFI) vulnerability, CVE-2026-12227, has been identified in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to 45.16.0. The flaw allows attackers to include and execute arbitrary files on the server through the vcv-template parameter, potentially leading to sensitive data exposure and Remote Code Execution (RCE) if the server is misconfigured. The vulnerability stems from a logic flaw in the PageTemplatesController.php file, where validation occurs before mutation, allowing crafted inputs to bypass security checks. The vulnerability was published on September 24, 2026, and a proof-of-concept (PoC) was made public on September 25, 2026. Users are urged to update to the latest version of the plugin to mitigate risks. The vulnerability has a CVSS score of 9.8, indicating its critical nature. Current exploitation status is confirmed as active, with reports of attacks in the wild. Security professionals are advised to assess their systems for affected versions and apply necessary patches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-12227 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…