We found a pre-authentication remote code execution flaw in SP Page Builder, the page builder for Joomla by JoomShaper, and reported it privately to the developers.
An unauthenticated visitor could make the site run a PHP file of their choosing from anywhere on the filesystem. It sits in the same part of the component that the previous update, 6.7.1, was supposed to have secured. It is fixed in SP Page Builder 6.8.0.
If you run SP Page Builder, update now. mySites.guru already flags every connected site still on a vulnerable version. Full write-up on the blog.
https://mysites.guru/.../sp-page-builder-pre-auth-rce.../...
Download the fixed version here.