PT-2026-46908 · Joomla · Jce Editor
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Widget Factory Joomla Content Editor (JCE) versions 1.0.0 through 2.9.99.4
Description
Improper access control in the JCE editor extension for Joomla allows unauthenticated users to create new editor profiles. This flaw enables the upload and execution of arbitrary PHP code on the affected server. The issue has been actively exploited in the wild to install web shells and establish persistent backdoors for ongoing unauthorized access and control.
Recommendations
Update Widget Factory Joomla Content Editor (JCE) to version 2.9.99.5.
Review access logs and editor profiles for signs of unauthorized user activity.
Exploit
Fix
RCE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jce Editor