External risk intelligence

Visual Composer WordPress Plugin Local File Inclusion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-12227

The vulnerability affects a WordPress plugin, which is designed to be part of a public-facing web application. WordPress sites are commonly exposed to the internet, and the plugin's functionality is accessible by default to unauthenticated users, making the vulnerable endpoint directly reachable from the public internet in standard deployments.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the Visual Composer Website Builder plugin for WordPress, allowing unauthenticated attackers to potentially execute arbitrary code on the server. This could lead to the compromise of sensitive data or the bypass of security controls. The main concern is confirming relevance and exposure, as this type of vulnerability could significantly impact systems accessible via the internet.

  • Unauthenticated attackers can run code on servers.
  • Affects WordPress sites using Visual Composer plugin.
  • Confirm if this plugin is used and exposed.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can leverage a weakness in the Visual Composer Website Builder plugin to include and execute arbitrary files on a WordPress server. This attack targets the `vcv-template` parameter, enabling the attacker to bypass security measures, access sensitive information, or execute code if certain file types can be uploaded and then included.

  • No authentication needed.
  • `vcv-template` parameter allows file inclusion.
  • Leads to sensitive data exposure or code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to include and execute arbitrary files on the server. When supported by the advisory, this may lead to the execution of any PHP code within those files, potentially enabling attackers to bypass access controls, acquire sensitive data, or achieve code execution, especially if image or other file type uploads are permitted and subsequently included.

  • Server files could be compromised.
  • Arbitrary file inclusion and execution.
  • Sensitive data exposure and code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Visual Composer Website Builder plugin for WordPress is susceptible to Local File Inclusion, allowing unauthenticated attackers to execute arbitrary files on the server. This vulnerability, present in all versions up to 45.16.0, can lead to bypassing access controls, data exfiltration, or code execution. Given the plugin's typical deployment in public-facing WordPress sites, immediate action is required to identify affected instances, confirm business criticality and reachability, assign ownership, and plan remediation.

  • Identify accountable application or platform owners.
  • Verify affected instances and their reachability.
  • Plan remediation and coordinate with vendors.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Visual Composer Website Builder plugin?

It is a WordPress plugin used to design and structure website layouts visually without requiring deep coding knowledge. By integrating directly into the WordPress environment, it handles content rendering and template management, which is how it interacts with the site's server-side file structure.

What does Local File Inclusion mean for CVE-2026-12227?

This vulnerability is classified as CWE-98, which involves improper control of file inclusion. Essentially, the plugin fails to properly validate user input, allowing an attacker to trick the system into loading and executing files that should not be accessible. This can lead to the server running unauthorized code.

How does an attacker trigger this vulnerability?

An attacker triggers the bug by sending a crafted request to the site using the 'vcv-template' parameter. Because the vulnerability does not require any login credentials, it can be initiated by anyone with network access to the site. Legitimate use of the plugin's standard interface does not trigger the bug.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal indicates a high likelihood of risk because this plugin is designed for public-facing websites. Since the vulnerable endpoint is accessible to unauthenticated users over the internet, any WordPress site running an affected version is directly reachable by external threats.

What should I do if I use this plugin?

You should first confirm which version of the Visual Composer plugin is currently installed on your WordPress instances. Once you identify all affected sites, prioritize them based on their reachability and business importance, then coordinate with your technical team to plan and apply the necessary vendor updates.

References