PT-2026-71078 · WordPress · Wp Page Builder
CVE-2026-67285
·
Published
2026-08-12
·
Updated
2026-08-13
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SP Page Builder versions prior to 6.8.0
Description
An unauthenticated attacker can perform local PHP file inclusion, allowing them to include arbitrary PHP files accessible by the system.
Recommendations
Update SP Page Builder to version 6.8.0 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Page Builder