WordPress 插件 FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment 在截至且包括 3.1.10 的所有版本中,通过 函数存在远程代码执行(RCE)漏洞。 该漏洞的成因是 中使用的正则黑名单极其容易被绕过,未能有效拦截 、 和 等 WordPress 核心函数;同时,通过 REST 接口存储的 PHP 条件规则值未经过任何净化处理。因此,具备作者(Author)级或更高权限的经过身份验证
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| fireplugins | FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment | 0 ~ 3.1.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet