Impact
The vulnerability allows an unauthenticated attacker to trigger the SP Page Builder extension for Joomla to include arbitrary local PHP files that are accessible to the system. This Local File Inclusion flaw (CWE-22) could enable an attacker to read sensitive files on the web server or execute PHP code if the attacker can influence the contents of the included file. The description does not confirm the ability to upload or otherwise weaponize files, so while the risk is significant, remote code execution is not explicitly stated.
Affected Systems
Joomla sites that host the SP Page Builder extension from joomshaper.com with a version earlier than 6.8.0 are affected. The flaw exists only in these older releases, so sites using 6.8.0 or later are not impacted.
Risk and Exploitability
The CVSS score of 9.2 indicates a high severity flaw. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is web‑based and requires no authentication, meaning anyone who can send a request to a vulnerable site can exploit the inclusion. Because the flaw permits access to any local PHP file, the potential impact on confidentiality, integrity, and availability is severe, but the exact exploitation probability cannot be quantified from the current data.
OpenCVE Enrichment