A vulnerability was found in WebsiteBaker up to 2.13.9. It has been classified as problematic. This affects the function save_droplet of the file modules of the component Droplets Editor. Performing a manipulation of the argument Code results in code injection.

This vulnerability is known as CVE-2026-61523. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.