Impact
The Joomla extension Quix Page Builder Pro for Joomla is vulnerable to authenticated PHP code execution. A user with builder privileges (core.create or core.edit) can inject PHP tags into the content of a page element; these tags are then executed by Joomla’s view-cache include() routine. This injection flaw provides attacker remote code execution capabilities on the site once caching is enabled, leading to full application compromise. The vulnerability is limited to authenticated users with builder rights.
Affected Systems
The vulnerability affects installations of the Quix Page Builder Pro extension distributed by themexpert.com for Joomla where the extension version is older than 6.2.1. Only sites that have Joomla’s caching enabled (the default setting) are susceptible; the core Joomla CMS and other extensions are not directly impacted.
Risk and Exploitability
The CVSS score of 8.9 indicates high severity. While the EPSS score is below 1% and the flaw is not yet listed in the CISA KEV catalog, the exploitation conditions—authenticated builder access and caching enabled—are commonly met on production sites. Based on the description, it is inferred that an attacker can inject PHP tags into element content, which are then executed by the view‑cache mechanism, resulting in remote code execution. This lowers the barrier to compromise and creates a significant risk for affected deployments.
OpenCVE Enrichment