Impact
Authenticated users with builder privileges can exploit the Quix Page Builder Pro extension for Joomla by inserting malicious script into id or class fields. These payloads are stored and rendered on public pages, causing script execution in visitors’ browsers. The issue arises from improper input validation in the extension’s page building interface and could lead to cross‑site scripting attacks that compromise user confidentiality and potentially allow credential theft or session hijacking.
Affected Systems
All Joomla sites that have installed the Quix Page Builder Pro extension with a version earlier than 6.2.1 are affected. The vulnerability is limited to the extension itself, not the core Joomla platform, and requires builder‑level access to create or edit pages.
Risk and Exploitability
Based on the description, the likely attack vector is internal to the CMS, as it requires authenticated builder user access. Once logged in, the attacker can persist malicious payloads in page content. With a CVSS score of 5.1, the vulnerability is of moderate severity, and an EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but because the malicious script runs in all site visitors’ browsers, the impact to users is significant.
OpenCVE Enrichment