Two critical vulnerabilities, both scoring 9.8 on the CVSS scale, were disclosed on September 24 and 25, 2026 in widely installed WordPress extensions. The first affects Visual Composer Website Builder, the second the Automation Web Platform – Notifications and OTP for WooCommerce plugin (WAWP), used for signups and one-time-password verification. Neither requires an account or any victim interaction to exploit.
Visual Composer: file inclusion via the vcv-template parameter
CVE-2026-12227 affects every version of Visual Composer Website Builder up to and including 45.16.0. It stems from missing validation on the vcv-template parameter, handled while the plugin’s internal controller resolves the WordPress template. An unauthenticated attacker can point that parameter at an arbitrary file on the server; when that file contains PHP code, it executes.
The exploitation conditions are trivial: a public page built with Visual Composer and a standard permalink are enough. Public proof-of-concept code is already circulating, which makes patching urgent for any exposed installation.
WAWP: from public signup to full administrator access
The second flaw, CVE-2026-14281, affects WAWP up to version 4.8.6. The public REST route /wp-json/wawp/v1/signup/<op> does not check the caller’s permissions, and the signup-completion function copies the attacker-controlled wawp_custom_fields parameter straight into the new user’s metadata without filtering. An attacker can inject the wp_capabilities and wp_user_level keys to create an administrator account directly.
The bypass goes further: when one-time-password verification is enabled, the session token is returned in plain text in the HTTP response, and the magic-link endpoint marks it as verified on any unauthenticated request carrying it, without ever checking the actual code. The two-step barrier — signup plus OTP — collapses into a single request.
| Plugin | CVE | CVSS | Affected versions | Disclosed |
|---|---|---|---|---|
| Visual Composer Website Builder | CVE-2026-12227 | 9.8 | ≤ 45.16.0 | September 24, 2026 |
| WAWP (Automation Web Platform) | CVE-2026-14281 | 9.8 | ≤ 4.8.6 | September 25, 2026 |
Mitigating before the update lands
While the patch is being rolled out, a web application firewall rule or a server-level block can cut off access to the affected parameters and routes:
# Blocks file-inclusion attempts via vcv-template (Visual Composer)
if ($arg_vcv-template ~* "\.\.|/etc/|php://") {
return 403;
}
# Blocks public access to the WAWP signup route
location ~ ^/wp-json/wawp/v1/signup/ {
deny all;
}
This does not replace updating the plugin, but it shrinks the exposure window while the update is being deployed, especially across fleets of sites managed at scale.
On both flaws, an attacker with no account gets either code execution or full administrator access, in a single HTTP request.
Both extensions see heavy use across the WooCommerce ecosystem and in brochure sites built with WPBakery/Visual Composer. A quick inventory of active plugins across managed fleets remains the most cost-effective first move before anything else.
The pace of these disclosures confirms a trend already visible in earlier WordPress flaws this week, including the critical fix in WordPress 7.1.2 and the Webform flaw in Drupal: targets are shifting from CMS cores toward third-party extensions, which are less audited and often installed without a formal security review. A baseline of WordPress hardening applied upfront limits the blast radius of this kind of incident, including on self-hosted infrastructure.
Key takeaways
Two heavily deployed WordPress extensions expose their sites to full compromise without any authentication. Updating to Visual Composer 45.16.1 or later and WAWP 4.8.7 or later should be treated as a priority, ahead of any other maintenance task scheduled this week.
Alerts like this land almost every week, and it is tempting to treat them as background noise. On the fleets I manage, it is precisely the most innocuous-looking extension — an OTP plugin, a page builder — that ends up opening the door, because nobody thinks to audit it with the same rigor as the WordPress core. An up-to-date plugin inventory is well worth the hour it costs — Simon Janvier.
Further reading: technical details on OffSeq Threat Radar.
