Impact
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin contains a flaw that allows authenticated users with author-level access and higher to execute arbitrary PHP code on the server. This occurs because the plugin’s Executer::allowedToRun() function uses a trivially bypassable regex blacklist that fails to block dangerous WordPress core functions such as wp_insert_user, update_option, and file_put_contents, and because PHP condition rule values are stored via the firebox_meta REST endpoint without sanitization. An attacker who exploits this can gain full control of the site, read, modify, and delete data, or use the server for further malicious activity. The vulnerability falls under privilege role modification (CWE‑269) and effectively escalates the attacker’s privileges from author to full code execution.
Affected Systems
All installations of the FireBox plugin with versions 3.1.10 and earlier, including sites that upgraded from earlier releases, are affected. The vendor is Fireplugins, and the product is the FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin. The issue was introduced by the Migrator::preserveCampaignRoleAccess() function, which automatically grants the edit_fireboxes and publish_fireboxes capabilities to the Author role in upgrades, thereby lowering the entry point to author-level access.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity vulnerability. EPSS data is not available, but the lack of a KEV listing and the nature of the issue suggest that exploitation would likely target sites with the plugin installed and run from the authenticated REST API. The attack requires only that the attacker have author or higher access; no additional privilege or network access is needed. Based on the description, the likely attack vector is via authenticated requests to the plugin’s core REST endpoint.
OpenCVE Enrichment