CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
ID: d69e19ec-ce23-5509-a9be-2b718e55c050
STIX ID: report--d69e19ec-ce23-5509-a9be-2b718e55c050
Feed Name: The Hacker News
The report describes a critical, actively exploited improper access control vulnerability in the Widget Factory Joomla Content Editor (CVE-2026-48907, CVSS 10.0) that allows unauthenticated creation of editor profiles to upload and execute PHP web shells, and separate large-scale WordPress supply-chain/compromise campaigns (involving OptinMonster, TrustPulse, PushEngage and a fake plugin) that inject malicious JavaScript, create persistent backdoor admin accounts or database-resident web shells for full server control and SEO monetization; CISA added the CVE to its KEV catalog and agencies were ordered to patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
