CVE-2026-60030 HIGH

CVE-2026-60030: Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1

Vendor Themexpert.com
Product Quix Page Builder Pro extension for Joomla
Weakness CWE-284
Published July 20, 2026
Last update July 23, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.

Explanation of Vulnerability in Simple Terms

02Summary

Quix Page Builder Pro for Joomla contains an access control flaw that allows unauthenticated attackers to read sensitive data over the network. The vulnerability affects versions 1.0-6.2.0 and requires no user interaction. Site administrators should update to a patched version when available.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the site without logging in.

Potential impact on your site

04Site Impact

Unauthorized visitors can access confidential information stored or processed by the page builder.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

July 20, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

08Related CVE