PT-2026-97774 · WordPress · Visual Composer Website Builder
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Visual Composer Website Builder versions prior to 45.16.1
Description
The plugin is subject to Local File Inclusion, a condition where an application includes files from the local file system without proper validation. Unauthenticated attackers can exploit this via the
vcv-template parameter to include and execute arbitrary files on the server. This allows for the execution of PHP code, bypassing access controls, and the retrieval of sensitive data, particularly when images or other safe file types can be uploaded and subsequently included.Recommendations
Update Visual Composer Website Builder to a version later than 45.16.0.
As a temporary mitigation, restrict access to the
vcv-template parameter.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Visual Composer Website Builder