Impact
The SP Page Builder extension for Joomla, provided by joomshaper.net, contains a flaw that allows anyone to upload files to the site without authentication. Once uploaded, the files are executed as PHP, enabling an attacker to run arbitrary code on the web server. This weakness falls under the CWE‑434 category of Unrestricted Upload of File with Dangerous Type.
Affected Systems
The vulnerable component is the SP Page Builder Joomla extension by joomshaper.net. All releases of the extension prior to version 6.6.2 are impacted. Joomla sites that have not applied the vendor’s 6.6.2 or later update remain susceptible, as the flaw is present in all older builds.
Risk and Exploitability
The CVSS score of 10 signals critical severity, and the EPSS score of 89% indicates a very high likelihood of exploitation. Because the upload endpoint permits unauthenticated requests and lacks type validation, an attacker can simply request the upload interface, inject a PHP script, and trigger its execution. The vulnerability is listed in the U.S. CISA Known Exploited Vulnerabilities catalog, confirming active exploitation attempts in the wild.
OpenCVE Enrichment