Overview Field Value CVE ID CVE-2026-12227 CVSS 3. 1 9. 8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CWE CWE-98 (Improper Control of Filename for Include/Require in PHP) Affected Visual Composer Website Builder WordPress plugin ≤ 45.
Source: [Dev.to](https://dev.to/guidance_white/cve-2026-12227-how-a-validate-then-mutate-bug-turns-into-unauthenticated-lfi-in-visual-composer-1aec)