The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Visual Composer Website Builder, a popular WordPress plugin used by thousands of websites, contains a critical Local File Inclusion (LFI) vulnerability affecting all versions up to 45.16.0. The flaw exists in the handling of the `vcv-template` parameter, which fails to properly validate user input before including files from the server filesystem. Because no authentication is required to exploit this vulnerability, any unauthenticated attacker can abuse this parameter to include arbitrary files—particularly PHP files—and execute malicious code directly on the server. The CVSS 9.8 critical rating reflects the severity: attackers can bypass access controls, exfiltrate sensitive data from configuration files, or achieve remote code execution without needing valid WordPress credentials.
While this CVE currently has zero mapped MITRE ATT&CK techniques and Casky skills, practitioners using Casky.ai's Claude-powered platform would detect the attack patterns through behavioral analysis of file inclusion attempts. Security teams should monitor for suspicious `vcv-template` parameter values in request logs, particularly those containing path traversal sequences (../, ..\) or attempts to include system files (/etc/passwd, wp-config.php). Casky's extended reasoning would help practitioners identify the attack chain: reconnaissance of the Visual Composer installation, crafting malicious LFI payloads to locate uploadable directories, and pivoting to code execution through previously uploaded files. Organizations running Visual Composer must immediately upgrade to a patched version and implement Web Application Firewall (WAF) rules to block requests with suspicious parameter values as an interim mitigation.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-12227. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation