Executive brief
ThemeXpert Quix Page Builder Pro, a popular drag-and-drop design tool for Joomla websites, contains a security flaw in its media management system. This vulnerability allows users who are logged into the site to upload files even if they do not have the specific administrative permissions required to manage media. This could lead to unauthorized storage usage or the placement of unwanted content on the web server.
Technical details
An improper access control vulnerability (CWE-284) exists in the Quix Page Builder Pro extension for Joomla (versions 1.0 through 6.2.0). The vulnerability resides in the media upload component, which fails to properly validate a user's specific media management privileges before processing file uploads. An authenticated attacker can bypass intended permission restrictions to upload files to the server. While the advisory notes the vulnerability is accessible to authenticated users, the provided CVSS 4.0 vector suggests a high impact on confidentiality (VC:H) and indicates a network-based attack vector.
Affected products
- ThemeXpert Quix Page Builder Pro extension for Joomla 1.0-6.2.0
Timeline
- 2026-07-20: disclosed
- 2026-07-20: advisory