Impact
The FireBox plugin contains a generic SQL injection vulnerability (CWE-89) in the Form Display Condition logic. Unsanitized user supplied parameters are directly interpolated into an existing SQL query without proper escaping or prepared statements. This flaw allows an authenticated user with Author or higher privileges to append arbitrary SQL commands, which can be used to extract sensitive database contents. Consequently an attacker can read private data such as user accounts, product details, or any other stored information accessed by the WordPress database.
Affected Systems
WordPress sites running the FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin (fireplugins) version 3.1.13 or earlier. The vulnerability is present in all releases up to and including 3.1.13 and affects sites that have not yet upgraded from an older version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available and the vulnerability is not listed by CISA in the KEV catalog, suggesting no publicly documented exploitation. Attackers require authenticated access; on fresh installs administrator privilege is required, whereas on previously upgraded sites author-level access suffices due to a migration script that grants edit_fireboxes capability to former edit_posts roles. Because the flaw is limited to authenticated users and no remote code execution path exists, the overall risk is considered moderate, yet remediation is advised to prevent possible data leakage.
OpenCVE Enrichment