CVE-2026-12227 is a local file inclusion vulnerability in the Visual Composer Website Builder plugin for WordPress affecting versions through 45.16.0. The vcv-template parameter permits unauthenticated attackers to include arbitrary files present on the server. Included files can be executed, enabling execution of PHP code contained in those files; attacker-controlled code execution may be possible when uploadable ostensibly safe file types can subsequently be included.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains one standalone Python 3 exploit program, an MIT license, and a README. The Python program is the functional entry point and supports either a single --url or a --targets file, bounded parallel scanning (maximum 20 threads), plugin fingerprinting, page-ID discovery/override, HTTP/HTTPS normalization, a check mode, and an exploit mode. It targets an alleged unauthenticated local-file-inclusion flaw in Visual Composer's vcv-template handling, where an attacker-controlled template path is passed to WordPress template inclusion. The exploit mode attempts to include target-side pearcmd.php, use PEAR's config-create behavior to create a temporary PHP file containing a command-execution expression, include that file, and optionally create and verify a PHP webshell in the uploads directory. The README is materially inconsistent with the Python-file header: it describes a different theme:-prefix traversal/validation-bypass mechanism and labels portions AI-reproduced, while the script header documents an absolute-path inclusion and PEAR-based chain. Accordingly, the Python code comments and exposed CLI behavior are the stronger evidence for the repository's intended capability; the exact vulnerability mechanics and version claims should be independently validated before relying on them.
The repository contains a single standalone Python 3 exploit program (CVE-2026-12227.py), an MIT license, and a README. It is not part of Metasploit, Nuclei, or another exploit framework. The Python program accepts either a single URL or a target list, supports up to 20 parallel threads, normalizes target URLs, fingerprints the Visual Composer plugin through its public readme, discovers or accepts a WordPress page ID, and provides check and exploit modes. Check mode is described as non-destructive. Exploit mode uses the vcv-template request parameter to force a local PHP include, targets pearcmd.php as an available local include gadget, creates a temporary executable PHP configuration file, executes a selectable command, and attempts persistence via a randomized PHP webshell under WordPress uploads. The README contains an explicitly AI-reproduced technical section that describes a different theme:-prefix validation-bypass mechanism than the primary script header's direct unvalidated-template explanation; therefore, the precise root-cause narrative should be independently validated. The active exploit logic and stated capabilities nevertheless target unauthenticated web-based local-file inclusion and conditional command execution.
This six-file repository is a standalone Python 3 exploit/scanner for CVE-2026-12227, affecting Visual Composer Website Builder WordPress plugin versions through 45.16.0. Its sole code entry point, poc.py, uses requests/urllib3 to normalize target URLs, identify the plugin via publicly accessible plugin files, parse versions, crawl common public paths or a supplied page, and look for Visual Composer HTML markers. It compares a normal response with requests containing vcv-template=blank, then sends LFI probes using vcv-template-type=vc and an attacker-controlled include path. Response heuristics detect passwd, wp-config, and WordPress version-file content. The tool supports a single target or concurrent mass scanning from a list, optional proxying, custom paths/page URL/include file, JSON output, and JSONL/text artifacts. README.md documents vulnerable conditions, examples, scan output, and FOFA discovery hints; targets.example.txt supplies benign sample input. No exploitation framework, shell payload, post-exploitation logic, or hardcoded external command-and-control infrastructure is present.
This nine-file repository is an authorized validation lab and exploit/verification toolkit for CVE-2026-12227, an unauthenticated local file inclusion flaw in Visual Composer Website Builder page-template handling. Its core defect is validate-then-mutate logic: validate_file() examines the raw vcv-template value, then all 'theme:' strings are stripped before locate_template() resolves the result. The supplied '.theme:./' fragments contain no literal '..' before validation but become '../' traversal segments after stripping. The primary executable PoC is poc/poc_cve_2026_12227.py. It fingerprints WordPress through /feed/ and Visual Composer through its public readme.txt, restricts use to loopback by default, and sends POST probes over homepage and page_id anchors, depths 3-6, using safe wp-links-opml.php and xmlrpc.php output oracles. It confirms successful inclusion and PHP execution but does not place files, execute commands, or implement an RCE payload. The included Nuclei template implements the same POST oracle technique with 20 request variants, redirects enabled, and stop-at-first-match behavior. The Bash lab driver and docker-compose.yml create a loopback-only Docker matrix using MySQL and WordPress. It downloads Visual Composer 45.16.1/45.16.3, provisions a theme and test page, and creates a lab-only uploads/mk-12227.php execution marker. The matrix demonstrates exploitation on WordPress 7.1.1 with Visual Composer 45.16.1 and 45.16.3, versus a silent result on WordPress 7.1.2. The repository attributes the latter to WordPress CVE-2026-87902's locate_template containment gate, which masks rather than fixes the Visual Composer code path. CI runs ./lab verify and then tears the lab down.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVE record is being created, but the content provides no technical description, affected product, impact, or exploit details.
An unauthenticated local file inclusion vulnerability in the Visual Composer Website Builder WordPress plugin, affecting versions through 45.16.0. Exploitation through the `vcv-template` parameter can include and execute server-side files, potentially bypassing access controls, exposing sensitive data, or achieving PHP code execution when an attacker can upload or otherwise make a suitable file available.
An unauthenticated local file inclusion vulnerability in Visual Composer Website Builder for WordPress through version 45.16.0. The `vcv-template` parameter can be used to include and execute arbitrary server-side files, potentially bypassing access controls, exposing sensitive data, and achieving PHP code execution when uploadable files can be included.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.