{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/visual-composer-website-builder--45.16.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:visualcomposer:visual_composer_website_builder:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-12227"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Visual Composer Website Builder (\u003c= 45.16.0)"],"_cs_severities":["critical"],"_cs_tags":["lfi","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["Visual Composer"],"content_html":"\u003cp\u003eThe Visual Composer Website Builder plugin for WordPress contains a critical Local File Inclusion (LFI) vulnerability identified as CVE-2026-12227. The flaw exists within the handling of the vcv-template parameter, which fails to properly sanitize user-supplied input before using it to include files on the server filesystem. An unauthenticated attacker can exploit this vulnerability to force the application to include and execute arbitrary local files, including those containing malicious PHP code. This capability allows attackers to bypass application-level access controls, exfiltrate sensitive configuration files such as wp-config.php, or achieve full Remote Code Execution (RCE) if the server permits the inclusion of attacker-controlled files like uploaded images containing embedded PHP payloads. This vulnerability affects all versions of the plugin up to and including 45.16.0.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary code with the privileges of the web server process. This can lead to total site compromise, data theft, and the establishment of persistent backdoors on the affected WordPress installation. The vulnerability is highly severe (CVSS 9.8) and impacts any WordPress site utilizing the Visual Composer Website Builder plugin within the affected version range.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Visual Composer Website Builder plugin to the latest available version (beyond 45.16.0) immediately.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect incoming HTTP requests for suspicious patterns in the vcv-template parameter, specifically looking for directory traversal sequences (e.g., ../) or unauthorized file extensions.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for requests containing the vcv-template parameter aimed at sensitive system files like /etc/passwd or application configuration files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T10:46:28Z","date_published":"2026-09-24T10:46:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-12227-lfi/","summary":"Visual Composer Website Builder for WordPress versions 45.16.0 and earlier are vulnerable to unauthenticated local file inclusion via the vcv-template parameter, allowing arbitrary file execution.","title":"Local File Inclusion in Visual Composer Website Builder Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-12227-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Visual Composer Website Builder (\u003c= 45.16.0)","version":"https://jsonfeed.org/version/1.1"}