Executive brief
Multiple Regular Labs extensions for the Joomla content management system are vulnerable to a security bypass. These extensions, which manage how and where content is displayed, incorrectly trust information provided by the user's browser regarding their location and IP address. This allows an attacker to trick the website into showing restricted content or applying rules intended for users in different geographic regions.
Technical details
A vulnerability exists in several Regular Labs extensions for Joomla (Advanced Module Manager, Conditional Content, Content Templater Pro, and ReReplacer Pro) where IP and GeoIP validation logic relies on untrusted HTTP forwarded headers (such as X-Forwarded-For). This is classified as CWE-290 (Authentication Bypass by Spoofing). A remote, unauthenticated attacker can spoof these headers to provide a fake IP address, effectively bypassing security or configuration rules that rely on geographic location or specific IP ranges. The issue affects multiple versions across the product suite as of July 2026.
Affected products
- Regular Labs Advanced Module Manager extension for Joomla 1.0.0-11.0.1
- Regular Labs Conditional Content extension for Joomla 1.0.0-6.0.0
- Regular Labs Content Templater Pro extension for Joomla 1.0.0-13.0.0
- Regular Labs ReReplacer extension Pro for Joomla 1.0.0-15.0.3
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory