A critical vulnerability, CVE-2026-56290, affects the Joomla Page Builder CK extension before version 3.6.0 and allows unauthenticated arbitrary file upload. The flaw can let remote attackers upload executable files and achieve full remote code execution, and it has been assigned a CVSS 4.0 score of 10.0. Belgium’s Centre for Cybersecurity issued a warning urging organizations to patch immediately because exposed Joomla sites using the vulnerable extension could be compromised without authentication.
Advisories recommend upgrading Page Builder CK to 3.6.0 or later, restricting upload permissions, and validating allowed file types to reduce exposure. Related vulnerability reporting published at the same time also highlighted a separate critical web CMS plugin issue, CVE-2026-57331, in the WordPress Paid Videochat Turnkey Site plugin through 7.4.8, where an arbitrary file deletion flaw rated CVSS 9.9 was remediated in 7.4.9 or later, underscoring continued risk from insecure file-handling bugs in widely deployed content management extensions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The Centre for Cybersecurity Belgium published an advisory warning that CVE-2026-56290 in the Joomla Page Builder CK extension can lead to remote code execution and urged immediate patching. This is a separate official warning about the same vulnerability.
CVE-2026-57331 was disclosed as a critical arbitrary file deletion vulnerability affecting the WordPress Paid Videochat Turnkey Site plugin version 7.4.8 and earlier. The reference says remediation is to update to version 7.4.9 or later.
A critical unauthenticated arbitrary file upload vulnerability, tracked as CVE-2026-56290, was disclosed for the Joomla Page Builder CK extension in versions earlier than 3.6.0. The flaw allows attackers to upload executable files and potentially achieve remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
ccb.belgium.be
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.