What is CVE-2026-48907?
CVE-2026-48907 is a critical improper access control vulnerability in the Widget Factory Joomla Content Editor plugin. It allows unauthenticated users to upload and execute arbitrary PHP code by creating new editor profiles. The vulnerability is actively exploited, so immediate patching is strongly recommended.
Azərbaycanca: CVE-2026-48907 Widget Factory Joomla Content Editor plagini üçün kritik bir boşluqdur. Bu zəiflik autentifikasiya olunmamış istifadəçilərə yeni redaktor profili yaradaraq ixtiyari PHP kodu yükləməyə və icra etməyə imkan verir. Bu boşluq aktiv şəkildə istismar edilir, ona görə də plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which plugin does CVE-2026-48907 affect?
This vulnerability affects the Widget Factory Joomla Content Editor plugin.
How to protect against CVE-2026-48907?
The plugin should be updated to the latest version immediately, as the vulnerability is actively exploited.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.