Hi Gregory,
We’re really sorry to hear about what happened to your websites. We completely understand how frustrating and concerning it must be to have your sites compromised and then experience another attack. We’re glad you had backups available to recover your sites.
We’d like to strongly recommend making sure you’re running the latest versions of our products:
- We have addressed the security issues identified in previous versions, with fixes included in 6.6.2, 6.8.0, and 6.9.1. Please update to the latest version, SP Page Builder Pro 6.9.1, as soon as possible.
- If you’re using a Helix Ultimate-based template, please also update the Helix Ultimate plugin to 2.2.10.
One important point: if a Joomla site has already been compromised, simply updating SP Page Builder may not be enough to secure the site. An attacker may have already placed a malicious file, backdoor, or other persistent code somewhere on the server. Updating the extensions will not automatically remove those files.
For an already compromised site, we recommend following our cleanup guide carefully:
How to clean an infected Joomla 4.x/5.x/6.x site
We genuinely appreciate you bringing this to our attention. We take security concerns very seriously, and we understand that protecting your websites and data is critical.
If you’re willing, please let us know the exact SP Page Builder version and Joomla version that were installed when the latest incident occurred.
We’d be happy to look into the situation further with you.
Best regards,