PT-2026-51135 · Joomla · Wp Page Builder

·

CVE-2026-48908

·

Published

2026-06-15

·

Updated

2026-08-13

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
Name of the Vulnerable Software and Affected Versions SP Page Builder for Joomla versions 1.0.0 through 6.6.1
Description A flaw in the SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, which can lead to the execution of PHP code on the server. The issue exists in the asset.uploadCustomIcon task, which accepts ZIP archives without requiring authentication or a CSRF token and extracts them into a web-reachable directory. Attackers can bypass file extension filters by using mixed-case extensions (e.g., .PHP) and uploading a .htaccess file to force the server to execute these files as PHP. This allows for the deployment of web shells, providing full filesystem access and command execution. Real-world exploitation has been observed targeting academic, government-adjacent, and commercial sites, with attackers deploying standalone file managers to maintain persistence.
Recommendations Update SP Page Builder for Joomla to version 6.6.2 or later. As a temporary workaround, block unauthenticated POST requests that include the task parameter set to asset.uploadCustomIcon.

Exploit

Fix

RCE

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09523
CVE-2026-48908

Affected Products

Wp Page Builder