S4E just found a medium-severity finding from [ai] private ip disclosure detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 28, 2026

CVE-2026-12227 Scanner

CVE-2026-12227 Scanner - Local File Inclusion (LFI) vulnerability in Visual Composer

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Visual Composer Website Builderby visualcomposer
0
Updated Sep 28, 2026View on NVD →
Detail

Visual Composer is a widely used website builder that integrates seamlessly with WordPress, allowing users to create visually dynamic web pages with ease. As a popular plugin, it is employed by web designers and developers globally to craft custom, responsive, and interactive websites. Releasing frequent updates, Visual Composer enhances creative possibilities and user experience by offering numerous design elements and professional templates. The tool's intuitive drag-and-drop interface is especially valuable for those with minimal coding experience. Due to its extensive adoption, any vulnerabilities, if present, pose a significant risk to countless websites. Consequently, routine security assessments are critical to the safety of sites relying on this powerful platform.

Local File Inclusion (LFI) is a severe vulnerability that allows attackers to include files on a server through the web browser. This issue within the Visual Composer plugin arises from inadequate validation of user-supplied input, specifically through external parameters. It is considered a critical vulnerability due to its potential to lead to full server compromise if exploited. Attackers can utilize LFI to execute arbitrary PHP code and access sensitive information without authenticated access. The vulnerability exists in versions <= 45.16.0, necessitating users of affected versions to implement corrective measures immediately. Recognizing such vulnerabilities early is key to preventing unauthorized access and potential data breaches.

The LFI vulnerability in Visual Composer, specifically in versions <= 45.16.0, centers on the 'vcv-template' parameter. Hackers can manipulate this parameter to exploit the web server's directory traversal capabilities. By injecting paths, unauthorized individuals can gain access to sensitive files such as '/etc/passwd'. Once embedded, these file paths facilitate the execution of arbitrary PHP code directly on the server. This breach therefore bypasses conventional authentication checks, exposing system control and sensitive data. Proper Patch management and eliminating outdated versions are crucial defenses against such exploitation vectors.

The exploitation of the Local File Inclusion vulnerability permits malicious actors to execute unintended actions on a web server. Consequences can range from server compromise to the unauthorized disclosure of sensitive information. With the ability to execute arbitrary PHP code, attackers might bypass access control measures, leading to full administrative rights acquisition. The arbitrary inclusion of files may even open pathways for further attacks, intensifying existing security risks. Unchecked, this exploitation may result in significant data breaches, highlighting the necessity for proactive security management practices.

REFERENCES

Solution Advice
Remediation:
  • Update Visual Composer to a version beyond 45.16.0 to eliminate the vulnerability.
  • Implement strict input validation to prevent injecting file paths into parameters.
  • Regularly audit and review plugin security updates to maintain a secure website environment.
  • Limit PHP execution permissions to essential directories only to reduce exposure.
  • Consider employing web application firewalls as an additional security measure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.