PT-2026-61673 · WordPress · Quix Page Builder Pro

CVE-2026-60026

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Quix Page Builder versions prior to 6.2.1
Description An authenticated user with core.create or core.edit permissions can execute arbitrary PHP code. This occurs when PHP tags are injected into element content, which are then executed through the include() function within the view-cache. This issue requires the caching feature to be enabled, which is the default configuration.
Recommendations Update Quix Page Builder to version 6.2.1 or later.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60026

Affected Products

Quix Page Builder Pro