Junglewise Threat Intelligence

CVE-2026-60026: ThemeXpert Quix Page Builder Pro PHP code injection in view-cache

CVE-2026-60026 · Severity: info · CVSS 8.9 · Published 2026-07-20

Technologies: ThemeXpert Quix Page Builder Pro. Vendors: ThemeXpert.

Executive brief

ThemeXpert Quix Page Builder Pro, a popular drag-and-drop design tool for Joomla websites, contains a vulnerability that allows authorized users with page-building permissions to execute malicious code on the server. By injecting PHP tags into page elements, an attacker can take full control of the website and its underlying server. This could lead to the theft of sensitive customer data, complete site defacement, or the installation of persistent backdoors.

Technical details

A code injection vulnerability (CWE-94) exists in the Quix Page Builder Pro extension for Joomla (versions 1.0 through 6.2.0). Authenticated users with 'core.create' or 'core.edit' permissions can inject PHP tags into page element content. This malicious code is subsequently executed when the Joomla view-cache processes the content via an include() call. The exploit requires the Joomla caching feature to be enabled, which is the default configuration. Successful exploitation allows for remote code execution (RCE) with the privileges of the web server user.

Affected products

  • ThemeXpert Quix Page Builder Pro extension for Joomla 1.0-6.2.0

Timeline

  • 2026-07-20: advisory: NVD publication date

References

Related threats