Junglewise Threat Intelligence

CVE-2026-60029: ThemeXpert Quix Page Builder Pro Stored XSS in id and class fields

CVE-2026-60029 · Severity: info · CVSS 5.1 · Published 2026-07-20

Executive brief

Quix Page Builder Pro, a popular drag-and-drop design tool for Joomla websites, contains a security vulnerability that allows authorized users with page-building permissions to inject malicious scripts. These scripts are stored on the website and can execute in the browsers of unsuspecting visitors. This could lead to unauthorized actions being performed on behalf of visitors or the theft of sensitive session information, potentially damaging the site's reputation and user trust.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Quix Page Builder Pro extension for Joomla (versions 1.0 through 6.2.0). The flaw is located within the handling of 'id' and 'class' fields in the page builder interface. An authenticated attacker with high-level privileges (builder users) can inject malicious JavaScript into these fields, which is then rendered without proper neutralization for public users. This allows for the execution of arbitrary code in the context of a victim's browser session. The vulnerability is tracked as CVE-2026-60029 and was assigned a CVSS 4.0 base score of 5.1 by the Joomla! Project.

Affected products

  • themexpert.com Quix Page Builder Pro extension for Joomla 1.0-6.2.0

Timeline

  • 2026-07-20: advisory: NVD publication date

References