Impact
The vulnerability arises from a missing access‑control check in the SP Page Builder extension’s menu‑item creation routine. The routine calls the Joomla core com_menus model’s save() method directly, but the model itself does not perform any authorization; the necessary checks exist result, any authenticated Joomla user – even one with no permissions on com_menus – can create new menu items or overwrite existing ones by submitting a jform[menuid] value. An attacker can therefore redirect the site, undermining the integrity and availability of the website’s menu structure.
Affected Systems
Vulnerable to all installations of the joomshaper.com SP Page Builder extension for Joomla, both the free and pro editions, with affected versions ranging from 4.0.0 through 6.9.0. Any site running one of those releases is susceptible.
Risk and Exploitability
The CVSS score of 5.1 classifies the flaw as moderate, reflecting that the exploitation requires authenticated access but does not provide direct code execution or disclose data. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers with a Joomla account, even with minimal privileges, can exploit this weakness by invoking the add‑to‑menu feature and supplying a target menu ID, thereby creating or overwriting site’s navigation and link structure, but this can be leveraged to hide malicious content or redirect users.
OpenCVE Enrichment