PT-2026-61675 · WordPress · Quix Page Builder Pro

CVE-2026-60028

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quix Page Builder versions prior to 6.2.1
Description An authenticated builder user can perform a stored Cross-Site Scripting (XSS) attack, which occurs when a malicious script is permanently stored on the target server. This is caused by unescaped output and unsanitized SVG files, allowing the injected scripts to execute for any visitor or administrator who views the affected page.
Recommendations Update Quix Page Builder to version 6.2.1 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60028

Affected Products

Quix Page Builder Pro