Mail Relay Vulnerability in SP Page Builder from JoomShaper
CVE-2026-65879
9.8CRITICAL
What is CVE-2026-65879?
A significant vulnerability exists in the SP Page Builder by JoomShaper affecting versions prior to 6.7.1, allowing attackers to exploit a hardcoded secret. This vulnerability enables unauthenticated mail relay attacks, permitting malicious entities to forge the 'From' address of email forms. This flaw poses a risk of email spoofing and can potentially be used to execute further attacks involving misinformation or phishing.
Affected Version(s)
SP Page Builder extension for Joomla 1.0.0-6.7.0
