
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-12227 is an unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder WordPress plugin affecting version 45.16.0 and earlier. The flaw allows unauthenticated attackers to supply untrusted input to a parameter that controls local file selection for inclusion, potentially bypassing access controls, exposing sensitive data, or executing PHP code contained in an includable file. The CVE is currently in "Reserved" status and was first indexed by Feedly on September 24, 2026. The vulnerability is estimated to be HIGH severity (Feedly, WPDeeply).
The root cause is improper neutralization of user-controlled input used to select a file for inclusion (CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program). Because no authentication is required and the parameter is not adequately sanitized or restricted, an attacker can craft a request that causes the PHP runtime to include an arbitrary local file — such as configuration files, log files, or other PHP-parseable files — from the server's filesystem. If the attacker can influence the content of an includable file (e.g., via log poisoning or file upload), this path can escalate to Remote Code Execution (RCE) (Feedly, WPDeeply).
Successful exploitation can result in unauthorized disclosure of sensitive server-side files (e.g., wp-config.php containing database credentials), bypass of access controls, and — under conditions where an attacker can write to an includable file — full Remote Code Execution on the hosting server. A compromised WordPress installation could serve as a pivot point for lateral movement within the hosting environment, credential theft, or deployment of web shells and malware (Feedly, WPDeeply).
The vulnerability requires no authentication, significantly lowering the barrier to exploitation and making it exploitable by any unauthenticated remote attacker. As of the time of reporting, the CVE is in "Reserved" status and no public proof-of-concept exploit code, exploit kit integration, in-the-wild exploitation, or CISA KEV catalog listing has been confirmed. No EPSS score or threat actor attribution is currently available (Feedly).
inurl:wp-content/plugins/visualcomposer).../../../../wp-config.php) in the vulnerable parameter.wp-config.php).../, ..%2F, ....//) in query or POST parameters; unexpected outbound connections from the web server process.wp-config.php or other sensitive files inconsistent with normal operations.bash, curl, wget) if RCE has been achieved via log poisoning or file upload chaining.Update the Visual Composer Website Builder plugin to a version later than 45.16.0 as soon as a patched release is made available by the vendor. In the interim, consider deactivating the plugin on internet-facing WordPress installations until a fix is confirmed. Additionally, implement a Web Application Firewall (WAF) rule to block requests containing path traversal sequences targeting the plugin's endpoints, and restrict PHP file inclusion via server-level configuration (e.g., open_basedir in php.ini) to limit the scope of exploitable files (WPDeeply).
Coverage of CVE-2026-12227 has been limited to a technical write-up published on WPDeeply, which details the nature of the LFI vulnerability in the Visual Composer Website Builder plugin. No official vendor statement from Visual Composer, broader media coverage, or notable researcher commentary has been identified at this time (WPDeeply).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"