POCBIT

CVE-2026-12227 — Visual Composer Website Builder ≤ 45.16.0 Unauthenticated LFI

Unauthenticated local file inclusion in **Visual Composer Website Builder** (≤ 45.16.0) via the **`vcv-template`** parameter (public Wordfence/NVD discussion).

#wordpress#visual-composer#lfi#unauthenticated

CVE:

CVE-2026-12227

Date:

2026-09-25

Severity:

HIGH

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-12227 is an unauthenticated local file inclusion in Visual Composer Website Builder for WordPress (≤ 45.16.0). The vcv-template code path is reported to allow inclusion of attacker-influenced template paths.

Impact

LFI can leak sensitive files (wp-config.php, environment files) and may combine with log poisoning or other tricks toward code execution.

Remediation

Upgrade Visual Composer Website Builder beyond the patched release cited in Wordfence/NVD entries.

Legal and ethical use

Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.

References

  • Look up the CVE ID on NVD and the CVE Program for official records.
  • Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.