<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Widget Factory</title><description>Actively exploited vulnerabilities affecting Widget Factory products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/widget-factory.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-48907 — Widget Factory Joomla Content Editor Improper Access Control Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-48907</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-48907</guid><description>This vulnerability in the Joomla Content Editor (JCE) plugin allows unauthenticated users — meaning anyone, no login required — to create new editor profiles and exploit them to upload and execute arbitrary PHP code on the server. Remote code execution by an unauthenticated attacker represents a critical risk: a successful exploit gives an attacker direct control over the web server, enabling data theft, defacement, backdoor installation, or use as a launchpad for further attacks.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Widget Factory</category><category>Joomla Content Editor </category></item></channel></rss>