Description
Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).
Published: 2026-07-20
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension Quix Page Builder Pro for Joomla is vulnerable to authenticated PHP code execution. A user with builder privileges (core.create or core.edit) can inject PHP tags into the content of a page element; these tags are then executed by Joomla’s view-cache include() routine. This injection flaw provides attacker remote code execution capabilities on the site once caching is enabled, leading to full application compromise. The vulnerability is limited to authenticated users with builder rights.

Affected Systems

The vulnerability affects installations of the Quix Page Builder Pro extension distributed by themexpert.com for Joomla where the extension version is older than 6.2.1. Only sites that have Joomla’s caching enabled (the default setting) are susceptible; the core Joomla CMS and other extensions are not directly impacted.

Risk and Exploitability

The CVSS score of 8.9 indicates high severity. While the EPSS score is below 1% and the flaw is not yet listed in the CISA KEV catalog, the exploitation conditions—authenticated builder access and caching enabled—are commonly met on production sites. Based on the description, it is inferred that an attacker can inject PHP tags into element content, which are then executed by the view‑cache mechanism, resulting in remote code execution. This lowers the barrier to compromise and creates a significant risk for affected deployments.

Generated by OpenCVE AI on August 3, 2026 at 01:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Quix Page Builder Pro to version 6.2.1 or later, which eliminates the PHP injection flaw.
  • If an upgrade is not possible, disable Joomla’s caching feature or set the view‑cache option to false to prevent execution of injected content.
  • Limit builder‑level permissions or configure Joomla’s input filtering/WAF rules to reject <php> or <? tags in page content.

Generated by OpenCVE AI on August 3, 2026 at 01:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla
Vendors & Products Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default). Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).
Title Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Themexpert.com Quix Page Builder Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:58:19.690Z

Reserved: 2026-07-08T05:31:35.889Z

Link: CVE-2026-60026

cve-icon Vulnrichment

Updated: 2026-07-21T16:27:34.015Z

cve-icon NVD

Status : Deferred

Published: 2026-07-20T19:17:26.920

Modified: 2026-07-23T16:17:30.423

Link: CVE-2026-60026

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:30:16Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')