CVE-2026-12227: Critical unauthenticated LFI in Visual Composer WordPress plugin
A critical flaw (CVE-2026-12227, CVSS 9.8) was found in the Visual Composer Website Builder WordPress plugin up to version 45.16.0. A validate-then-mutate bug lets an unauthenticated attacker include an arbitrary file with a single HTTP request, potentially leading to code execution. It is fixed in 45.16.1.
- CVSS 3.1 score 9.8, CWE-98, no authentication required
- Affects Visual Composer ≤ 45.16.0, fixed in 45.16.1
- Bug in viewPageTemplate(): validate_file() runs before str_replace('theme:')
- Fragmented payload bypasses the check, enabling LFI and possible RCE
Read next
Security