Executive brief
The UP plugin extension for Joomla allows unauthenticated attackers to install arbitrary code remotely on affected systems. This vulnerability could enable an attacker to take complete control of a website, access sensitive data, or use the compromised server for malicious purposes without requiring valid credentials.
Technical details
The UP plugin extension for Joomla contains an unauthenticated remote code installation vulnerability affecting versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29. The vulnerability allows unauthenticated network-based attackers to install arbitrary code without any prior authentication or user interaction, leading to complete system compromise.
Affected products
- lomart.fr UP plugin 5.0.0-5.2.0, 6.0.0-6.0.29
Timeline
- 2026-09-26: disclosed