Megamenu was Hacked, Database Injected - Question | JoomShaper

Megamenu was Hacked, Database Injected

J

jcalvert

SP Page Builder 1 week ago

Hello,

I just encounted one of my websites using SP Page Builder Pro, current version.

The Home page menu link was hacked and JS code injected.

Please contact me asap for details.

0
4 Answers
J
jcalvert
Accepted Answer
1 week ago #229246

OK, this was caused because the JoomShaper template that I'm using uses Helix Ultimate, which also required an update due to CVE-2026-57829. I wasn't aware of that.

My other websites using Helix were not affected, because they are not using Helix Ultimate (not even installed). I had updated to Helix 3.1.2.

PLEASE post a pinned security warning that Helix Ultimate also need to be updated to the current version, 2.2.9. (Vulnerabilities were fixed in vers. 2.2.7, as per the change log).

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 1 week ago #229277

Hello jcalvert,

Thank you for reaching out to our technical support forum. I’m sorry to hear about the trouble you have experienced.

We have already fixed the issues and notified our users. We even solved the issues for old Joomla 3 users too. Please check out this article for details:

Security Update

Best regards

0
J
jcalvert
Accepted Answer
1 week ago #229278

OK, thanks.

I didn't get any notification about this, which is why I suggested that you create a separate email list that customers can subscribe to, so that they can get security alerts very quickly.

I had no idea about this blog article, https://www.joomshaper.com/blog/security-update-for-joomla-3-users, and I see it was only posted yesterday, July 15th.

I went to this forum for help, so I'm sure other people are doing that, which is why you should link the blog article as a pinned post to the forum, don't you think?

thank you

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 4 days ago #229877

Thank you for your suggestion. I hope the management will consider it.

0