The FireBox WordPress plugin is vulnerable to authenticated Remote Code Execution via an insufficiently validated blacklist and improper input sanitization in the firebox_meta REST endpoint.
FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment
web-application
wordpress
rce
authentication-bypass
2t
1c