VulnerabilityBleeping Computer
9.8 — CRITICAL
CISA orders feds to patch max severity Joomla plugin flaw by Friday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory Joomla Content Editor (JCE) plugin that is being actively exploited in the wild. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A maximum-severity vulnerability in the Widget Factory Joomla Content Editor plugin is being actively exploited, allowing threat actors to achieve code execution via low-complexity attacks targeting unauthenticated users. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch the flaw by Friday.
⚙️Technical Details
💥Impact Assessment
Severity: critical
🛡️Recommended Actions
1Update to JCE Pro 2.9.99.6 or later
2Back up rogue profiles for further investigation and delete attacker's profile
3Change all passwords (including administrator account, site's database, and hosting account) and run a full server-side malware scan
📦Affected Products
Product Name: Widget Factory Joomla Content Editor pluginCve Id: CVE-2026-48907
🔐NVD Verified DataVERIFIED
Weaknesses
CWE-284
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
