Hello,
We sincerely apologize for the inconvenience caused.
This issue has been fixed from SP Page Builder v6.6.2. Once you upgrade to latest one, v6.8.0, this specific vulnerability can no longer be exploited.
However, if your site was compromised before upgrading, simply updating the extension will not remove any malicious files or backdoors that may have already been uploaded. If those files remain on the server, attackers may still be able to access your site. Therefore, it is important to perform a complete cleanup before considering the site secure.
Please, follow this documentation: https://www.joomshaper.com/documentation/sp-page-builder/troubleshooting#how-to-clean-an-infected-joomla-4x-6x-site
After completing the cleanup and upgrading to v6.8.0, please let us know the outcome or if you need any further assistance.
We'll be happy to help.
Thank you.