Vulnerability Analysis: CVE-2026-12227 Visual Composer <= 45.16.0 – Unauthenticated LFI
Introduction In the landscape of web application security, WordPress plugins are frequently targeted due to their widespread deployment. The Visual Composer Website Builder, a highly popular page builder plugin for WordPress, was found to contain a critical security flaw designated as CVE-2026-12227. This vulnerability, affecting versions up to and including 45.16.0, allows unauthenticated attackers to exploit a Local File Inclusion (LFI) vulnerability. Due to its