ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-12057
The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE

NVD description · AI analysis pending
9.8<1%
  • WordPress
CVE-2025-12352
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all vers

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This only impacts sites that have allow_url_fopen set to `On`, the post creation form enabled along with a file upload field for the post

NVD description · AI analysis pending
9.81%
  • WordPress
CVE-2025-32432
Code Injection Enables Remote Code Execution in Craft CMS

Craft CMS contains a code injection vulnerability (CWE-94) that allows a remote attacker to execute arbitrary code on affected servers. CISA's listing does not specify the exact attack path or authentication requirements, but the flaw is remotely triggerable and grants arbitrary code execution, which typically means full compromise of the web server and a foothold for follow-on activity such as ransomware (ransomware use is not yet confirmed). Any organization running a Craft CMS instance is in scope, including internet-facing content sites and deployments where the Craft admin panel is reachable from the internet. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-20, confirming exploitation in the wild, and EPSS assigns a 99.8% probability of exploitation within 30 days (100th percentile), although no public proof-of-concept is known. No CVSS score has been published yet, so defenders should treat the flaw as urgent given the KEV listing and near-certain EPSS likelihood.

Do: Apply the patched Craft CMS release per the vendor's security advisory referenced in CISA's KEV entry (specific fixed version numbers are not provided in the source data), prioritizing internet-exposed instances, and U.S. federal agencies should follow BOD 22-01 requirements for KEV-listed flaws. Until patched, restrict network access to the Craft CMS control panel/admin interface and review web and application logs for signs of code injection or unexpected process execution, since exploitation in the wild is confirmed while ransomware use remains unknown. Given the 99.8% EPSS score and KEV listing, treat discovery and patching of all Craft CMS instances, including headless deployments, as an urgent, time-boxed task.

10.0100% KEV PoC
  • Craft CMS
mass≈100,000–200,000+ live Craft CMS sites (order of magnitude: ~10^5 internet-facing deployments)
CVE-2025-6389
Unauthenticated Remote Code Execution in Sneeit Framework WordPress Plugin

CVE-2025-6389 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in the Sneeit Framework plugin for WordPress, affecting every version up to and including 8.3. The sneeit_articles_pagination_callback() function takes input supplied by the request and passes it directly to PHP's call_user_func(), so an unauthenticated attacker can send crafted input that causes the server to invoke attacker-chosen PHP functions. Successful exploitation yields arbitrary code execution on the server, which attackers can use to inject backdoors, create new administrative WordPress accounts, or take full control of the site and potentially the underlying host. Any WordPress site running the Sneeit Framework plugin at version 8.3 or earlier is affected. The flaw is not in CISA's KEV and no public proof-of-concept is known, but EPSS puts its exploitation probability in the next 30 days at 76.1% (100th percentile), and security reporting indicates it is already being exploited in the wild.

Do: Update Sneeit Framework to the latest patched release (any version newer than 8.3); if updating is not immediately possible, deactivate or remove the plugin, or apply a WAF/virtual-patching rule that blocks the vulnerable pagination callback endpoint. Because the flaw is already exploited in the wild, sites that ran version 8.3 or earlier should audit wp_users for rogue administrator accounts, look for injected backdoors (unexpected PHP files, modified core/theme files, suspicious scheduled tasks), and review web access logs for exploitation attempts. Monitor the vendor and Wordfence advisories for the fixed version number and any indicators of compromise.

9.876%
  • Sneeit Framework (WordPress plugin) all versions up to and including 8.3
largeon the order of tens of thousands of WordPress sites (~10^4 installs, per the plugin's modest WordPress.org active-install count)
CVE-2025-7852
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via t

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and including, 1.0.6. The plugin’s image‐upload handler calls move_uploaded_file() on client‐supplied files without restricting allowed extensions or MIME types, nor sanitizing the filename. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

NVD description · AI analysis pending
9.82%
  • WordPress
CVE-2026-0740
Unauthenticated Arbitrary File Upload RCE in Ninja Forms File Uploads WordPress Plugin

CVE-2026-0740 is a critical (CVSS 9.8) unauthenticated arbitrary file upload vulnerability in the Ninja Forms - File Uploads plugin for WordPress, affecting all versions up to and including 3.3.26. It is caused by missing file type validation in the NF_FU_AJAX_Controllers_Uploads::handle_upload function, so anyone can send a crafted request to the plugin's upload AJAX endpoint with no account, no privileges, and no user interaction. Because uploaded file types are not validated, an attacker can plant arbitrary files, such as PHP scripts, on the web server, which may enable remote code execution and full compromise of the site. Any WordPress site running the File Uploads add-on for Ninja Forms at version 3.3.26 or earlier is exposed, especially sites that accept front-end uploads from visitors. The flaw was partially patched in 3.3.25 and fully fixed in 3.3.27; no public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 62.9% EPSS score (99th percentile) signals a high likelihood of exploitation within 30 days.

Do: Update the Ninja Forms - File Uploads add-on to version 3.3.27 or later, since 3.3.25-3.3.26 contain only a partial fix. Until patched, restrict or disable unauthenticated front-end uploads and block unauthenticated requests to the plugin's upload AJAX endpoint via WAF rules. Audit the uploads directories for unexpected PHP files or webshells, as arbitrary uploads may have enabled code execution.

9.863%
  • Ninja Forms (Saturday Drive) Ninja Forms - File Uploads (WordPress plugin/add-on) <= 3.3.26 (partially patched in 3.3.25; fully patched in 3.3.27)
largelikely tens of thousands of sites (roughly 10,000-100,000; premium add-on to a core plugin with ~900k+ active installs)
CVE-2026-29014
Unauthenticated PHP Code Injection RCE in MetInfo CMS

CVE-2026-29014 is an unauthenticated PHP code injection flaw (CWE-94) in MetInfo CMS, caused by insufficient neutralization of user-supplied input in an execution path that evaluates PHP. A remote attacker needs no privileges or user interaction and triggers the flaw simply by sending crafted requests containing malicious PHP, which the server then executes. Successful exploitation results in full remote code execution, giving the attacker complete control over the affected web server and everything it hosts. All MetInfo CMS 7.9, 8.0, and 8.1 deployments are affected, with risk concentrated in internet-facing installations. Exploitation has been reported in the wild, public PoCs are available, and the 39.5% EPSS score (99th percentile) signals high near-term exploitation risk, though the flaw is not yet listed in CISA KEV.

Do: Upgrade MetInfo CMS to the latest patched release; the advisory flags 7.9, 8.0, and 8.1 as affected, so confirm the exact fixed version in the vendor's advisory before upgrading, and prioritize internet-facing instances. Until patched, restrict or WAF-filter HTTP access to MetInfo endpoints and review access logs for crafted requests containing injected PHP syntax. Use the public PoC write-ups (Karmain Security KIS-2026-06 and WebSec) to identify the vulnerable request pattern when hunting for signs of compromise.

9.339% PoC ×2
  • metinfo 7.9, 8.0, 8.1
largeon the order of 100,000+ deployments (order-of-magnitude estimate; no authoritative install count published)
CVE-2026-3395
A flaw has been found in MaxSite CMS up to 109.1.

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 109.2 will fix this issue. This patch is called 08937a3c5d672a242d68f53e9fccf8a748820ef3. You should upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.

NVD description · AI analysis pending
5.54%
  • max-3000 maxsite cms
CVE-2026-3844
Unauthenticated Arbitrary File Upload in Breeze Cache WordPress Plugin

CVE-2026-3844 is a critical (CVSS 9.8) arbitrary file upload vulnerability in the Breeze Cache plugin for WordPress, caused by missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to and including 2.4.4. An unauthenticated attacker can trigger the function over the network and upload arbitrary files to the affected site's server, but the flaw is only exploitable when the 'Host Files Locally - Gravatars' option is enabled, which is disabled by default. Uploaded files can include executable PHP such as web shells, so successful exploitation may make remote code execution and full site or server compromise possible. Any WordPress site running Breeze Cache 2.4.4 or earlier with local Gravatar hosting switched on is affected, and press coverage reports more than 400,000 sites at risk. Headlines indicate attackers are already exploiting the flaw in the wild; no public proof-of-concept is known, the EPSS score of 27.7% (98th percentile) signals high near-term exploitation risk, and the CVE is not yet in CISA's KEV.

Do: Sites running Breeze Cache should update to the latest patched release (any version after 2.4.4); if updating is not immediately possible, disable the 'Host Files Locally - Gravatars' setting to close the attack path. Administrators should also audit uploaded files and the webroot for unexpected PHP files or web shells and check site integrity for signs of compromise, given reports of active exploitation and related WordPress backdoor campaigns.

9.828%
  • Cloudways Breeze Cache plugin for WordPress <= 2.4.4 (all versions up to and including 2.4.4)
mass≈400,000+ WordPress sites at risk
CVE-2026-48907
Unauthenticated PHP Code Upload and Execution in Joomla Content Editor (JCE)

CVE-2026-48907 is an improper access control flaw (CWE-284) in the Joomla Content Editor (JCE) extension from Widget Factory Limited that allows unauthenticated users to create new editor profiles. Because these profiles can confer file-upload privileges, an attacker can reach the editor's upload functionality without logging in, upload malicious PHP files, and have the web server execute them, resulting in unauthenticated remote code execution with high impact on system confidentiality, integrity, and availability (CVSS 4.0 score of 10). Any Joomla site running the affected JCE extension is exposed, with internet-facing sites most at risk. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-16, confirming in-the-wild exploitation, and EPSS assigns a 78.1% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is known, but CISA and Australian authorities have warned of active CMS exploitation targeting this flaw.

Do: Apply the latest JCE update per Widget Factory Limited's vendor instructions, in line with CISA BOD 26-04 requirements (federal agencies must patch or discontinue use of the product if mitigations are unavailable). Until patched, verify whether unauthenticated users can create editor profiles in your JCE configuration, restrict access to the extension, and inspect webroots and logs for unexpected PHP file uploads. Given confirmed active exploitation and a very high EPSS score, prioritize internet-facing Joomla sites immediately.

10.078% KEV PoC
  • Widget Factory Limited Joomla Content Editor (JCE)
masson the order of 100,000+ Joomla sites (estimate)
CVE-2026-48939
Unauthenticated File-Upload RCE in Joomlic iCagenda for Joomla

Joomlic's iCagenda event-management extension for Joomla contains an unrestricted file-upload flaw (CWE-434) in its file attachment feature, exploitable over the network without authentication or user interaction (CVSS 4.0 score 10.0). Because the extension accepts arbitrary file types, an attacker can upload a malicious PHP file through the attachment feature and have the web server execute it as PHP code. Successful exploitation gives unauthenticated attackers remote code execution on the affected Joomla site, which typically leads to full site or web-server compromise. Any Joomla installation running the iCagenda extension is affected; the available advisory data specifies no affected or fixed version range, so no version numbers can be stated. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-10 (reportedly exploited as a zero-day, with ransomware use currently unknown), public proof-of-concept code is available, and EPSS assigns roughly a 20% probability of exploitation within 30 days.

Do: Joomla administrators running iCagenda should update to the latest release published by Joomlic (no specific fixed version is stated in the available data) and, per the KEV required action, apply vendor mitigations in accordance with CISA BOD 26-04, prioritizing internet-exposed instances. Until patched, restrict or disable the file-attachment upload feature (e.g., prevent PHP execution/uploads in the attachments directory) and review web server logs and upload directories for unexpected .php files indicating prior compromise. Given confirmed in-the-wild exploitation reportedly predating disclosure, assume potential compromise and follow CISA's forensics triage requirements where applicable.

10.020% KEV PoC
  • Joomlic iCagenda (Joomla extension)
moderatelikely thousands to tens of thousands of Joomla sites (estimate; no install-count data in the source record)
CVE-2026-56291
Unauthenticated File Upload RCE in Balbooa Forms (Joomla)

CVE-2026-56291 is an unauthenticated unrestricted file upload flaw (CWE-434) in the Balbooa Forms extension for Joomla, affecting versions prior to 2.4.1. Because the upload functionality requires no authentication, any remote attacker who can reach a site running the extension can upload arbitrary files, including executable file types, to the web server. Uploaded executable files can subsequently be invoked on the server, resulting in full remote code execution with high impact on confidentiality, integrity, and availability. Any Joomla site running Balbooa Forms below version 2.4.1 is affected, particularly those whose upload functionality is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-10 after reportedly being exploited as a zero-day, and a public proof-of-concept write-up is available.

Do: Upgrade Balbooa Forms to version 2.4.1 or later immediately, as patching is the required action under CISA KEV/BOD 26-04 guidance. If upgrading is not immediately possible, restrict unauthenticated access to the extension's upload functionality at the web server or WAF layer and inspect upload directories for unexpected executable files that would indicate compromise. Review web logs for unauthenticated upload requests from unknown sources and treat any findings as potential RCE incidents.

10.015% KEV PoC
  • Balbooa Forms (Joomla extension) < 2.4.1
unknown (no public install or exposure counts available for the Balbooa Forms extension)
Full article683 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 13, 2026Vulnerability / Web Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.

The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below -

  • CVE-2026-48939 - A vulnerability in the iCagenda extension for Joomla that allows the upload of arbitrary files via the file attachment feature, leading to PHP code upload and execution.
  • CVE-2026-56291 - A vulnerability in the Balbooa Forms extension for Joomla that allows the upload of arbitrary files, leading to remote code execution.

According to mySites.guru, a cloud-based dashboard service for managing WordPress and Joomla websites, CVE-2026-48939 is said to have been exploited as a zero-day since June 15, 2026, in automated attacks aimed at Joomla sites on which iCagenda is installed. It resides in the "Submit an Event" form functionality, which lets users propose events for the calendar.

"We first saw it in a client's access log: an automated scanner identifying itself as 'icagenda-batch/1.0' grabbed a token, posted a malicious upload to the submit endpoint, then fetched the planted shell at the exact path the component writes attachments to," mySites.guru said.

The flaw impacts the following versions -

  • 4.x versions up to and including 4.0.7
  • Legacy 3.x versions from 3.2.1 up to and including 3.9.14

JoomliC has since released updates to address the issue in iCagenda versions 4.0.8 and 3.9.15. Site owners are advised to check for suspicious PHP files in the "images/icagenda/frontend/attachments/" folder and remove them.

MySites.guru said it also observed zero-day exploitation of CVE-2026-56291, which affects Balbooa Forms versions up to and including 2.4.0. It has been patched in version 2.4.1.

"Up to and including version 2.4.0, its frontend attachment upload had a serious flaw: it accepted a file from any anonymous visitor, with no login, no CSRF token, and no check on the file type," it said. "An attacker could upload a PHP file into a public folder and then run it, which is unauthenticated remote code execution, the worst outcome a web flaw can have."

The vulnerability was discovered by mySites.guru on July 8, 2026, following a live attack on one of its customers. It has shared the following indicators of compromise -

  • Look in the Balbooa Forms upload folder (by default "images/baforms/uploads") for any file that is not an image or document, especially anything ending in PHP
  • Check the Joomla user list for suspicious administrator accounts
  • Audit the set for recently modified or unfamiliar PHP files across the site

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have until July 13, 2026, to implement the fixes in their networks.

Australia Warns of Global Campaign Targeting Vulnerable CMS Systems

The disclosure comes as the Australian Cyber Security Centre (ACSC) issued an alert warning of a global exploitation campaign targeting various vulnerabilities in content management systems (CMS) and plugins.

"As part of this campaign, malicious cyber actors are actively scanning websites for opportunities to deploy web shells, leveraging various vulnerabilities affecting CMS software and plugins," the agency said. "These vulnerabilities primarily allow unauthenticated file upload, remote code execution, server side request forgery or deserialization."

Once deployed, the web shells serve as conduits for remote access and control of the targeted web servers. Some of the identified security vulnerabilities are listed below -

"This highly scaled global exploitation campaign demonstrates the rapidly evolving cyber risk facing organisations," ACSC said, adding "advances in AI are accelerating the speed and scale of cyber operations, reducing the time between vulnerability disclosure and exploitation."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/icagenda-and-balbooa-forms-joomla-flaws.html