Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A critical unauthenticated remote code execution vulnerability in the Widget Factory Joomla Content Editor plugin allows attackers to create rogue editor profiles and execute arbitrary PHP code on affected web servers. CISA has confirmed active exploitation in the wild and assigned a remediation due date of June 19, 2026. Any organization running this plugin on an internet-facing Joomla instance faces full server compromise without requiring any user interaction or credentials.

Author

Tech Jacks Solutions