Executive brief
JoomShaper SP Page Builder, a popular tool for building websites on the Joomla platform, contains a critical security flaw that allows anyone on the internet to upload files to the server without logging in. An attacker can use this to upload malicious scripts and take full control of the website. This vulnerability has been reported as being actively exploited in the wild, posing an immediate risk to site operations and data security.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in the SP Page Builder extension for Joomla. The flaw allows unauthenticated remote attackers to bypass security checks and upload arbitrary files, including PHP scripts, to the web server. This is achieved via a network request to a vulnerable component, such as the 'uploadcustomicon' function. Successful exploitation leads to Remote Code Execution (RCE) with the privileges of the web server user. The vulnerability is reportedly being exploited in the wild as a zero-day. Users should update to version 6.6.2 or later to remediate the issue.
Affected products
- JoomShaper SP Page Builder extension for Joomla 1.0.0 through 6.6.1
Timeline
- 2026-06-20: disclosed: Initial disclosure by Joomla! Project
- 2026-06-20: advisory: NVD published date
- 2026-06-22: exploited: Reported as exploited in the wild (zero-day)
- 2026-06-30: patched: Fix identified in version 6.6.2