Joomla · Jce Editor · CVE-2026-48907
**Name of the Vulnerable Software and Affected Versions**
Widget Factory Joomla Content Editor (JCE) versions 1.0.0 through 2.9.99.4
**Description**
Improper access control in the JCE editor extension for Joomla allows unauthenticated users to create new editor profiles. This flaw enables the upload and execution of arbitrary PHP code on the affected server. The issue has been actively exploited in the wild to install web shells and establish persistent backdoors for ongoing unauthorized access and control.
**Recommendations**
Update Widget Factory Joomla Content Editor (JCE) to version 2.9.99.5.
Review access logs and editor profiles for signs of unauthorized user activity.