Vulnerabilities
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
Cyber RTJune 17, 20263 min read

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical security flaw in Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities catalog, citing active exploitation. The flaw, CVE-2026-48907, allows unauthorized PHP code execution. It affects JCE versions up to 2.9.99.4, patched in version 2.9.99.5. Concurrently, WordPress sites face a supply chain attack, injecting malicious JavaScript and compromising site security.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a critical security flaw affecting the Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog. This decision was made due to evidence of active exploitation of the vulnerability, which is tracked as CVE-2026-48907. The flaw has been assigned a maximum severity score of 10.0 on the CVSS scale, indicating its potential impact. The vulnerability involves improper access control that could allow attackers to execute arbitrary code.
CISA has detailed that the vulnerability in the Widget Factory Joomla Content Editor could enable the upload and execution of PHP code by creating new editor profiles for unauthenticated users. This security gap resides in the JCE editor extension for Joomla, which could be exploited by malicious actors to gain unauthorized access. The flaw affects JCE versions from 1.0.0 through 2.9.99.4, but it has been addressed in version 2.9.99.5, released on June 3, 2026. Widget Factory acknowledged that the issue stemmed from insufficient access controls.
Currently, there is no detailed information available about how the vulnerability is being exploited in real-world scenarios. However, Federal Civilian Executive Branch (FCEB) agencies have been instructed to implement the necessary fixes by June 19, 2026, to mitigate potential risks. This proactive measure is crucial to prevent exploitation and protect sensitive systems from unauthorized access and code execution.
In parallel with the Joomla vulnerability disclosure, a new supply chain attack campaign has been identified, targeting over 1 million WordPress sites. This campaign involves the use of OptinMonster, TrustPulse, and PushEngage WordPress plugins, where threat actors inject malicious JavaScript. The injected code waits for a logged-in administrator to create a backdoor admin account and installs a self-hiding backdoor plugin, compromising the site's security.
Another campaign has been discovered where attackers compromise a WordPress site by embedding a fake plugin named "Beloved PBN Entegrasyonu." This plugin stealthily communicates the site's URL to an external API and injects arbitrary HTML or JavaScript into the web page's footer. The exact method of breaching the website remains unclear, but attackers have managed to stage two PHP web shells, granting them extensive access to the server's file system.
The database-resident payloads used by the attackers allow them to perform various file actions, such as reading, writing, editing, or deleting files on the server. They can also browse directories, change file permissions, rename files, create new files and folders, and upload files from their own computers. This level of access poses significant risks to the compromised sites, including potential data breaches and unauthorized modifications.
According to Sucuri researcher Puja Srivastava, every visitor to the compromised site receives injected outbound links in their page source, which can damage the site's search rankings and result in penalties from Google Search Console. The campaign is reportedly operated by a Turkish-speaking threat actor and revolves around a classic SEO monetization scheme. This involves hidden backlink injection for a Private Blog Network (PBN), likely linked to the gambling and adult affiliate niche, further highlighting the diverse motivations behind such cyberattacks.


