PT-2026-61675 · WordPress · Quix Page Builder Pro
CVE-2026-60028
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Quix Page Builder versions prior to 6.2.1
Description
An authenticated builder user can perform a stored Cross-Site Scripting (XSS) attack, which occurs when a malicious script is permanently stored on the target server. This is caused by unescaped output and unsanitized SVG files, allowing the injected scripts to execute for any visitor or administrator who views the affected page.
Recommendations
Update Quix Page Builder to version 6.2.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quix Page Builder Pro