CVE-2026-12227 — Visual Composer Website Builder ≤ 45.16.0 Unauthenticated LFI
Unauthenticated local file inclusion in **Visual Composer Website Builder** (≤ 45.16.0) via the **`vcv-template`** parameter (public Wordfence/NVD discussion).
Description
Overview
CVE-2026-12227 is an unauthenticated local file inclusion in Visual Composer Website Builder for WordPress (≤ 45.16.0). The vcv-template code path is reported to allow inclusion of attacker-influenced template paths.
Impact
LFI can leak sensitive files (wp-config.php, environment files) and may combine with log poisoning or other tricks toward code execution.
Remediation
Upgrade Visual Composer Website Builder beyond the patched release cited in Wordfence/NVD entries.
Legal and ethical use
Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.
References
- Look up the CVE ID on NVD and the CVE Program for official records.
- Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.