Description
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to block WordPress core functions such as wp_insert_user, update_option, and file_put_contents, combined with no sanitization of PHP condition rule values stored via the firebox_meta REST endpoint. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server. On sites upgraded from a version prior to 3.1.10, the Migrator::preserveCampaignRoleAccess() function automatically grants the edit_fireboxes and publish_fireboxes capabilities to the Author role, lowering the effective entry point to Author-level access.
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin contains a flaw that allows authenticated users with author-level access and higher to execute arbitrary PHP code on the server. This occurs because the plugin’s Executer::allowedToRun() function uses a trivially bypassable regex blacklist that fails to block dangerous WordPress core functions such as wp_insert_user, update_option, and file_put_contents, and because PHP condition rule values are stored via the firebox_meta REST endpoint without sanitization. An attacker who exploits this can gain full control of the site, read, modify, and delete data, or use the server for further malicious activity. The vulnerability falls under privilege role modification (CWE‑269) and effectively escalates the attacker’s privileges from author to full code execution.

Affected Systems

All installations of the FireBox plugin with versions 3.1.10 and earlier, including sites that upgraded from earlier releases, are affected. The vendor is Fireplugins, and the product is the FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin. The issue was introduced by the Migrator::preserveCampaignRoleAccess() function, which automatically grants the edit_fireboxes and publish_fireboxes capabilities to the Author role in upgrades, thereby lowering the entry point to author-level access.

Risk and Exploitability

The CVSS score of 8.8 classifies this as a high‑severity vulnerability. EPSS data is not available, but the lack of a KEV listing and the nature of the issue suggest that exploitation would likely target sites with the plugin installed and run from the authenticated REST API. The attack requires only that the attacker have author or higher access; no additional privilege or network access is needed. Based on the description, the likely attack vector is via authenticated requests to the plugin’s core REST endpoint.

Generated by OpenCVE AI on September 9, 2026 at 04:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the FireBox plugin to the latest version that addresses the RCE flaw.
  • If an upgrade is not immediately possible, revoke the edit_fireboxes and publish_fireboxes capabilities that may have been granted to the Author role during migration, using a role editor or user‑role management plugin.
  • Disable or restrict access to the firebox_meta REST endpoint, ensuring that only trusted and properly authenticated users can invoke it, to prevent malicious payload submission.

Generated by OpenCVE AI on September 9, 2026 at 04:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Fireplugins
Fireplugins firebox – Woocommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment
Wordpress
Wordpress wordpress
Vendors & Products Fireplugins
Fireplugins firebox – Woocommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to block WordPress core functions such as wp_insert_user, update_option, and file_put_contents, combined with no sanitization of PHP condition rule values stored via the firebox_meta REST endpoint. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server. On sites upgraded from a version prior to 3.1.10, the Migrator::preserveCampaignRoleAccess() function automatically grants the edit_fireboxes and publish_fireboxes capabilities to the Author role, lowering the effective entry point to Author-level access.
Title FireBox <= 3.1.10 - Authenticated (Author+) Remote Code Execution to Privilege Escalation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Fireplugins Firebox – Woocommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T13:56:02.046Z

Reserved: 2026-08-19T19:45:45.314Z

Link: CVE-2026-76801

cve-icon Vulnrichment

Updated: 2026-09-09T13:55:58.030Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T03:17:24.943

Modified: 2026-09-09T15:33:47.627

Link: CVE-2026-76801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:47Z

Weaknesses
  • CWE-269

    Improper Privilege Management