
Proof-of-concept and technical analysis for CVE-2026-12227, an unauthenticated LFI in the WordPress Visual Composer plugin (<=45.16.0) enabling file inclusion and RCE.
CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to and including 45.16.0. The flaw is in the vcv-template parameter, which allows an attacker to include and execute arbitrary files on the server. This can lead to sensitive data exposure, access control bypass, or even full Remote Code Execution (RCE) if the server environment is misconfigured.
CVE-2026-12227
9.8/10
Visual Composer Website Builder Plugin (upto version 45.16.0)
Root cause: The vulnerability is classified as CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program (often referred to as PHP Remote File Inclusion). It stems from a logic flaw in the PageTemplatesController.php file, specifically within the viewPageTemplate() function, which hooks into WordPress's template_include filter at priority 11 without any authentication check.
The core issue is a "validate-then-mutate" flaw:
Validation (on raw input): The code first calls WordPress's validate_file() function on the raw, user-supplied value of the vcv-template parameter. This function is designed to reject paths containing literal directory traversal sequences like ... At this stage, the malicious input theme:.theme:./.theme:./.theme:./wp-links-opml.php contains no literal .., so it passes validation.
Mutation (after validation): Immediately after validation, the code checks if the template type is vc-custom-layout and if the value contains the string theme:. If so, it performs str_replace('theme:', '', $current['value']), which removes all occurrences of theme: from the value.
Sink: The mutated value is then passed to locate_template(), which resolves the path and includes the file. Because the theme: strings were stripped, the fragmented traversal sequences are fused together, creating a valid path like ../../../../wp-links-opml.php that was never validated in its final form.
Attack Surface: Attack Vector: Network (AV:N) — the vulnerability is reachable directly over HTTP/HTTPS.
Authentication: None required (PR:N) — it is an unauthenticated vulnerability. Any remote attacker can trigger it without a valid account.
User Interaction: None required (UI:N).
Affected Component: The Visual Composer Website Builder plugin for WordPress.
Vulnerable Parameter: The vcv-template parameter, used in conjunction with the vcv-template-type parameter.
Trigger Condition: The plugin must be installed and active on a WordPress site, and a front-end page must be built with Visual Composer (i.e., a normal permalink must exist).
Exploitation Notes: Impact: The flaw allows an unauthenticated attacker to include and execute arbitrary local files on the server. Because included PHP files are executed, this can lead to Remote Code Execution (RCE) , allowing for a full compromise of the server's confidentiality, integrity, and availability.
Exploitation Technique: Attackers can exploit this by crafting a malicious vcv-template value that uses the theme: prefix to bypass validation, as described in the root cause. For example, a request might look like: POST /?vcv-template-type=vc-custom-layout&vcv-template=theme:.theme:./.theme:./.theme:./wp-links-opml.php.
RCE Escalation: While the LFI itself is critical, achieving RCE often depends on the server environment. A common method is to include a file that has already been uploaded to the server (e.g., a seemingly harmless image file containing embedded PHP code) or to leverage other server misconfigurations.
PoC Availability: Multiple proof-of-concept exploits are publicly available, including a Python script and a Nuclei template, which can be used for validation in authorized lab environment
[*] Python Code Given Above
Patch version: 45.16.1