PT-2026-51135 · Joomla · Wp Page Builder
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red |
Name of the Vulnerable Software and Affected Versions
SP Page Builder for Joomla versions 1.0.0 through 6.6.1
Description
A flaw in the SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, which can lead to the execution of PHP code on the server. The issue exists in the
asset.uploadCustomIcon task, which accepts ZIP archives without requiring authentication or a CSRF token and extracts them into a web-reachable directory. Attackers can bypass file extension filters by using mixed-case extensions (e.g., .PHP) and uploading a .htaccess file to force the server to execute these files as PHP. This allows for the deployment of web shells, providing full filesystem access and command execution. Real-world exploitation has been observed targeting academic, government-adjacent, and commercial sites, with attackers deploying standalone file managers to maintain persistence.Recommendations
Update SP Page Builder for Joomla to version 6.6.2 or later.
As a temporary workaround, block unauthenticated POST requests that include the
task parameter set to asset.uploadCustomIcon.Exploit
Fix
RCE
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Page Builder