Widget Factory Joomla Content Editor Vulnerability
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
CVSS Score
9.8
CRITICAL
Published
16 Jun 2026 00:00
Modified
N/A
Vendor
Widget Factory
Product
Joomla Content Editor
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-284
Affected Systems
Widget Factory
Joomla Content Editor
Widget Factory
Joomla Content Editor
External Links
KEV Status
Known Exploited Vulnerability