PT-2026-88768 · Fireplugins · Firebox – Woocommerce Popup Builder

·

CVE-2026-76801

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to block WordPress core functions such as wp insert user, update option, and file put contents, combined with no sanitization of PHP condition rule values stored via the firebox meta REST endpoint. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server. On sites upgraded from a version prior to 3.1.10, the Migrator::preserveCampaignRoleAccess() function automatically grants the edit fireboxes and publish fireboxes capabilities to the Author role, lowering the effective entry point to Author-level access.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76801

Affected Products

Firebox – Woocommerce Popup Builder