<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Joomlack</title><description>Actively exploited vulnerabilities affecting Joomlack products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/joomlack.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-56290 — Joomlack Page Builder Improper Access Control Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-56290</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-56290</guid><description>This vulnerability in Joomlack&apos;s Page Builder extension allows unauthenticated attackers to upload arbitrary files to a target system, which can lead directly to remote code execution. Because no login is required to exploit it, the attack surface is effectively anyone who can reach the web server. A successful exploit gives an attacker the ability to run malicious code on the server, potentially leading to full system compromise, data theft, or use as a pivot point for deeper network access.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>Joomlack</category><category>Page Builder</category></item></channel></rss>