Skip to content
THREATWIRE

News

Visual Composer LFI is CVE-2026-12227

Wordfence disclosed an unauthenticated local file inclusion in the Visual Composer Website Builder WordPress plugin up to 45.16.0, CVSS 9.8. A public PoC repository exists. Exploitation in the wild and CISA KEV listing are not confirmed.

Critical

Published 5 Oct 2026

What happened

On 24 September 2026 Wordfence published CVE-2026-12227 for the Visual Composer Website Builder plugin for WordPress. The record describes local file inclusion through the vcv-template parameter, reachable without authentication. Wordfence scored it 9.8 under CVSS 3.1 and classified it as CWE-98. A public repository presented as a PoC for this CVE was created the same day, and posts about it are now circulating.

Who is affected

Every site running Visual Composer Website Builder at version 45.16.0 or earlier is affected, according to the CVE record. This is the free page builder published on WordPress.org under the slug visualcomposer, with more than 40,000 active installations. It is a different product from WPBakery Page Builder, which is sometimes still called Visual Composer. Patchstack lists 45.16.1 as the first patched version, and WordPress.org currently ships 45.16.3.

What is confirmed

The CVE record confirms an unauthenticated file inclusion that can execute PHP contained in files on the server. Wordfence says it can be used to bypass access controls, read sensitive data, or run code when an attacker can get an includable file onto the site, for example through uploads of types usually treated as safe. NVD published the entry on 24 September 2026, and its own analysis is Deferred, so the 9.8 score comes from Wordfence. The public PoC repository exists, which sets the record's availability to PoC.

What is not confirmed

CISA has not added CVE-2026-12227 to the Known Exploited Vulnerabilities catalog, and no source used here reports exploitation in the wild. The headline claim of full site compromise depends on conditions, such as an includable file with PHP content, that the advisory states but does not show as default. The WordPress.org changelog for 45.16.1 does not mention this fix, there is no separate Visual Composer security bulletin, and a GitHub Security Advisory could not be verified. ThreatWire did not review or reproduce the PoC.

What to do

Update Visual Composer Website Builder to 45.16.1 or later, ideally the current 45.16.3 release from WordPress.org. If an update cannot happen right away, deactivate the plugin until it can, since the vulnerable parameter needs no login. After updating, review upload and writable directories for unexpected PHP content and check access logs for unusual requests carrying the vcv-template parameter.

Sources: Wordfence Intelligence, NVD, the CVE.org record, WordPress plugin changeset 3619572, and Patchstack, all linked from the record.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/visual-composer-lfi-is-cve-2026-12227

More articles