{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/firebox/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:firebox:firebox:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-76801"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin \u0026 Cart Abandonment (\u003c= 3.1.10)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","rce","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["FireBox"],"content_html":"\u003cp\u003eThe FireBox plugin for WordPress (all versions up to and including 3.1.10) contains a critical Remote Code Execution (RCE) vulnerability. The flaw exists in the Executer::allowedToRun() function, which relies on a regex blacklist that fails to restrict sensitive WordPress core functions such as wp_insert_user, update_option, and file_put_contents. Because the plugin does not perform adequate input sanitization on PHP condition rule values passed through the firebox_meta REST endpoint, an attacker can supply malicious payloads.\u003c/p\u003e\n\u003cp\u003eFurthermore, a privilege escalation vector exists within the Migrator::preserveCampaignRoleAccess() function. When updating from versions prior to 3.1.10, the plugin automatically assigns edit_fireboxes and publish_fireboxes capabilities to the Author role. This effectively lowers the barrier to entry for exploitation, allowing any authenticated user with Author-level privileges to achieve server-side code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers with Author-level access to execute arbitrary PHP code on the underlying web server. This can lead to full site compromise, unauthorized database modification, or the installation of persistent web shells. The vulnerability affects all users running FireBox version 3.1.10 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the FireBox plugin to the latest version immediately to resolve the vulnerable regex blacklist and sanitize inputs in the firebox_meta endpoint.\u003c/li\u003e\n\u003cli\u003eAudit existing user accounts with Author roles to identify and remediate accounts that may have gained unnecessary permissions following the migration to version 3.1.10.\u003c/li\u003e\n\u003cli\u003eMonitor REST API traffic for POST requests targeting the 'firebox_meta' endpoint containing suspicious function calls or serialized PHP objects.\u003c/li\u003e\n\u003cli\u003eImplement strict web application firewall (WAF) rules to inspect incoming requests for function names like 'file_put_contents' or 'wp_insert_user' within JSON bodies destined for the WordPress REST API.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T03:51:57Z","date_published":"2026-09-09T03:51:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-firebox-rce/","summary":"The FireBox WordPress plugin is vulnerable to authenticated Remote Code Execution via an insufficiently validated blacklist and improper input sanitization in the firebox_meta REST endpoint.","title":"Remote Code Execution in FireBox WooCommerce Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-firebox-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - FireBox","version":"https://jsonfeed.org/version/1.1"}