CVE-2026-60026 HIGH

CVE-2026-60026: Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1

Vendor Themexpert.com
Product Quix Page Builder Pro extension for Joomla
Weakness CWE-94 · Code injection
Published July 20, 2026
Last update July 23, 2026

CVSS base score

8.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).

Explanation of Vulnerability in Simple Terms

02Summary

Quix Page Builder Pro for Joomla contains a code injection vulnerability in versions 1.0-6.2.0. An authenticated administrator can inject and execute arbitrary PHP code through the extension's input handling. This allows complete control over the Joomla site, including data theft, malware installation, and site defacement.

What an attacker can do

03Attacker Capabilities

Run arbitrary PHP code on the Joomla site with full administrative privileges.

Potential impact on your site

04Site Impact

A compromised admin account can be used to inject malicious code, steal data, install backdoors, or take the site offline.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level access to the Joomla backend.

Key dates

06Disclosure timeline

July 20, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

08Related CVE