Impact
Conditional Content Pro accepts inline PHP in article syntax. In affected Joomla versions, the PHP is evaluated without checking the author, so a privileged user can inject malicious code that runs as the web‑server process. The resulting code execution gives the attacker full control over the site.
Affected Systems
All sites running the Conditional Content Pro extension for Joomla below version 8.0.0 are affected. The vulnerability is specific to users who have authenticated access with privileges to create or edit articles.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity, and the vulnerability requires authentication but provides privileged access to execute arbitrary code. The EPSS score is 0.00485, and the vulnerability is not yet listed in the CISA KEV catalog, but the high CVSS score and remote code execution capability make it a high‑value target for attackers. A privileged attacker could gain full control of the web server, exfiltrate data, or deploy additional malware.
OpenCVE Enrichment