Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-12227 — Proof-of-concept and technical analysis for CVE-2026-12227, an unauthenticated LFI/RCE in the WordPress Visual Composer plugin via the vcv-template parameter. | Kitploit
Tools/GitHubGitHub/mrdark-ops/cve-2026-12227
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubmrdark-ops/cve-2026-12227

CVE-2026-12227

Proof-of-concept and technical analysis for CVE-2026-12227, an unauthenticated LFI/RCE in the WordPress Visual Composer plugin via the vcv-template parameter.

View Repository
12 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-12227: Visual Composer Website Builder Unauthenticated Local File Inclusion (LFI)



Summary

CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to and including 45.16.0. The flaw is in the vcv-template parameter, which allows an attacker to include and execute arbitrary files on the server. This can lead to sensitive data exposure, access control bypass, or even full Remote Code Execution (RCE) if the server environment is misconfigured.

CVE ID

CVE-2026-12227

CVSS

9.8/10

Affected Products

Visual Composer Website Builder Plugin (upto version 45.16.0)

Technical Details

Root cause: The vulnerability is classified as CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program (often referred to as PHP Remote File Inclusion). It stems from a logic flaw in the PageTemplatesController.php file, specifically within the viewPageTemplate() function, which hooks into WordPress's template_include filter at priority 11 without any authentication check.

The core issue is a "validate-then-mutate" flaw:

Validation (on raw input): The code first calls WordPress's validate_file() function on the raw, user-supplied value of the vcv-template parameter. This function is designed to reject paths containing literal directory traversal sequences like ... At this stage, the malicious input theme:.theme:./.theme:./.theme:./wp-links-opml.php contains no literal .., so it passes validation.

Mutation (after validation): Immediately after validation, the code checks if the template type is vc-custom-layout and if the value contains the string theme:. If so, it performs str_replace('theme:', '', $current['value']), which removes all occurrences of theme: from the value.

Sink: The mutated value is then passed to locate_template(), which resolves the path and includes the file. Because the theme: strings were stripped, the fragmented traversal sequences are fused together, creating a valid path like ../../../../wp-links-opml.php that was never validated in its final form.

Attack Surface: Attack Vector: Network (AV:N) — the vulnerability is reachable directly over HTTP/HTTPS.

Authentication: None required (PR:N) — it is an unauthenticated vulnerability. Any remote attacker can trigger it without a valid account.

User Interaction: None required (UI:N).

Affected Component: The Visual Composer Website Builder plugin for WordPress.

Vulnerable Parameter: The vcv-template parameter, used in conjunction with the vcv-template-type parameter.

Trigger Condition: The plugin must be installed and active on a WordPress site, and a front-end page must be built with Visual Composer (i.e., a normal permalink must exist).

Exploitation Notes: Impact: The flaw allows an unauthenticated attacker to include and execute arbitrary local files on the server. Because included PHP files are executed, this can lead to Remote Code Execution (RCE) , allowing for a full compromise of the server's confidentiality, integrity, and availability.

Exploitation Technique: Attackers can exploit this by crafting a malicious vcv-template value that uses the theme: prefix to bypass validation, as described in the root cause. For example, a request might look like: POST /?vcv-template-type=vc-custom-layout&vcv-template=theme:.theme:./.theme:./.theme:./wp-links-opml.php.

RCE Escalation: While the LFI itself is critical, achieving RCE often depends on the server environment. A common method is to include a file that has already been uploaded to the server (e.g., a seemingly harmless image file containing embedded PHP code) or to leverage other server misconfigurations.

PoC Availability: Multiple proof-of-concept exploits are publicly available, including a Python script and a Nuclei template, which can be used for validation in authorized lab environment

  • This section was reproduced by AI because i was too lazy to write it all

Proof of Concept

[*] Python Code Given Above

Remediation

Patch version: 45.16.1

References

  • CVE.org: https://www.cve.org/CVERecord?id=CVE-2026-12227
  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-12227
  • MITRE CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12227
  • VulDB: https://vuldb.com/?search=CVE-2026-12227
  • Wordfence Intelligence: https://www.wordfence.com/threat-intel/vulnerabilities/
  • Patchstack: https://patchstack.com/database/
  • WPScan: https://wpscan.com/vulnerability/
  • Exploit-DB: https://www.exploit-db.com/search?cve=2026-12227
  • GitHub Search: https://github.com/search?q=CVE-2026-12227
  • Nuclei Templates: https://github.com/projectdiscovery/nuclei-templates
  • CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • Rapid7: https://www.rapid7.com/db/
  • Tenable: https://www.tenable.com/cve/CVE-2026-12227
  • Snyk: https://security.snyk.io/vuln/?search=CVE-2026-12227
  • Aqua: https://avd.aquasec.com/nvd/cve-2026-12227
  • CVE Details: https://www.cvedetails.com/cve/CVE-2026-12227/
  • CIRCL: https://cve.circl.lu/cve/CVE-2026-12227
  • GitHub Advisory: https://github.com/advisories?query=CVE-2026-12227
  • Packet Storm: https://packetstormsecurity.com/search/?q=CVE-2026-12227
  • Sploitus: https://sploitus.com/?query=CVE-2026-12227
  • Vulmon: https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12227
  • CVEFeed: https://cvefeed.io/vuln/detail/CVE-2026-12227
  • OpenCVE: https://www.opencve.io/cve/CVE-2026-12227
  • CVE.report: https://cve.report/CVE-2026-12227
  • Vulners: https://vulners.com/cve/CVE-2026-12227
  • Security-Database: https://www.security-database.com/cve/CVE-2026-12227
  • CVE Crowd: https://cvecrowd.com/cve/CVE-2026-12227
  • CVE Base: https://www.cvebase.com/cve/2026/12227
Download Tool