CVE-2026-12227
Visual Composer unauthenticated local file inclusion
Wordfence says CVE-2026-12227 lets an unauthenticated attacker include and execute local files through the vcv-template parameter of the Visual Composer Website Builder WordPress plugin, up to and including 45.16.0. CVSS 3.1 score 9.8. A public PoC repository exists. CISA has not listed it in KEV.
- CVSS
- 9.8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Class
- Other
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Visual Composer
- Products
- Visual Composer Website Builder (WordPress plugin)
- Affected
- All versions up to and including 45.16.0.
- Fixed
- 45.16.1 and later, per Patchstack. The current WordPress.org release is 45.16.3.
- CWE
- CWE-98
- Published
- 24 Sept 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-12227 is a local file inclusion flaw in the Visual Composer Website Builder plugin for WordPress. Wordfence, the CVE Numbering Authority, says the vcv-template parameter lets an unauthenticated attacker include and execute files on the server, in all versions up to and including 45.16.0. CWE-98. The CVSS 3.1 score from Wordfence is 9.8.
The advisory says this can bypass access controls, expose sensitive data, or lead to code execution when an includable file, including some upload types usually treated as safe, contains PHP. NVD published the record on 24 September 2026 and its own analysis is marked Deferred, so the score is the CNA's, not an NVD assessment.
Patchstack lists 45.16.1 as the patched version and WordPress.org currently ships 45.16.3. The WordPress.org changelog entry for 45.16.1 does not name this issue, and there is no separate vendor security bulletin. A public PoC repository was created on 24 September 2026. CISA has not added the CVE to the KEV catalog, and no source confirms exploitation in the wild. This record does not reprint requests or payloads.