Description
Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.
Published: 2026-07-20
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a broken access control (CWE‑284) in the Quix Page Builder Pro extension for Joomla. Authenticated users can upload media files even if they lack media‑management permissions, undermining the integrity of the site’s media library and potentially allowing the addition of malicious content. While the description does not explicitly state that executable files can be uploaded, the ability to upload arbitrary files suggests that attackers could choose to upload harmful files if they wish.

Affected Systems

Vulnerable installations are those running the Quix Page Builder Pro extension from themexpert.com on Joomla, with a version older than 6.2.1. Sites that rely on this extension for page building and have not applied the update remain affected.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is less than 1%, suggesting exploitation is presently rare, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with access to the extension’s web interface; no external or unauthenticated vector is disclosed.

Generated by OpenCVE AI on August 3, 2026 at 01:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Quix Page Builder Pro to version 6.2.1 or later
  • Revoke media upload privileges from non‑administrator Joomla roles if a patch cannot be applied immediately
  • Scan the media library for and delete any files uploaded before the fix, then monitor upload activity for anomalies

Generated by OpenCVE AI on August 3, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla
Vendors & Products Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions. Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.

Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.
Title Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Themexpert.com Quix Page Builder Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:57:16.645Z

Reserved: 2026-07-08T05:31:35.889Z

Link: CVE-2026-60030

cve-icon Vulnrichment

Updated: 2026-07-20T20:14:22.447Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:30:16Z

Weaknesses