A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. An unauthenticated attacker over the network can upload arbitrary files and execute PHP code on the server.