Helix3 Template (shaper_helix3) below 3.1.2 - Unauthenticated File Write/Delete via com_ajax (RCE, CVE-2026-49049)
The Helix3 template framework's com_ajax plugin handler (plugins/ajax/helix3/helix3.php, onAjaxHelix3) performs a file write/delete reachable without authentication: no authorise() or session-token gate on a guest com_ajax request. Fixed in Helix3 3.1.1 (JoomShaper security release, 29 Jun 2026); the patched build closes multiple unauthenticated vectors in the handler, not only the reported actions. CVE pending (credited to Phil Taylor, Blue Flame Digital Solutions). Update to 3.1.1 or later. Affected 1.0-3.1.1 (CVE-2026-49049); fixed in Helix3 3.1.2.
Affected versions: < 3.1.2
Full advisory: www.joomshaper.com

