PT-2026-97774 · WordPress · Visual Composer Website Builder

·

CVE-2026-12227

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Visual Composer Website Builder versions prior to 45.16.1
Description The plugin is subject to Local File Inclusion, a condition where an application includes files from the local file system without proper validation. Unauthenticated attackers can exploit this via the vcv-template parameter to include and execute arbitrary files on the server. This allows for the execution of PHP code, bypassing access controls, and the retrieval of sensitive data, particularly when images or other safe file types can be uploaded and subsequently included.
Recommendations Update Visual Composer Website Builder to a version later than 45.16.0. As a temporary mitigation, restrict access to the vcv-template parameter.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12227

Affected Products

Visual Composer Website Builder