Description
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. On fresh installations of version 3.1.10 and later, exploitation requires administrator-level access; however, on sites upgraded from a version prior to 3.1.10, the preserveCampaignRoleAccess() migration grants the edit_fireboxes capability to any role that previously held edit_posts, reducing the minimum required privilege to Author-level.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized data disclosure via SQL injection
Action: Immediate patch
AI Analysis

Impact

The FireBox plugin contains a generic SQL injection vulnerability (CWE-89) in the Form Display Condition logic. Unsanitized user supplied parameters are directly interpolated into an existing SQL query without proper escaping or prepared statements. This flaw allows an authenticated user with Author or higher privileges to append arbitrary SQL commands, which can be used to extract sensitive database contents. Consequently an attacker can read private data such as user accounts, product details, or any other stored information accessed by the WordPress database.

Affected Systems

WordPress sites running the FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin (fireplugins) version 3.1.13 or earlier. The vulnerability is present in all releases up to and including 3.1.13 and affects sites that have not yet upgraded from an older version.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS score is available and the vulnerability is not listed by CISA in the KEV catalog, suggesting no publicly documented exploitation. Attackers require authenticated access; on fresh installs administrator privilege is required, whereas on previously upgraded sites author-level access suffices due to a migration script that grants edit_fireboxes capability to former edit_posts roles. Because the flaw is limited to authenticated users and no remote code execution path exists, the overall risk is considered moderate, yet remediation is advised to prevent possible data leakage.

Generated by OpenCVE AI on October 10, 2026 at 05:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update FireBox to the latest version that resolves the SQL injection flaw. If a newer release is unavailable, upgrade to a patched version recommended by the vendor.
  • If an upgrade is not possible, temporarily disable or remove the FireBox plugin and review all popup configurations to ensure no residual code remains.
  • Revoke the edit_fireboxes capability from the Author role (or any role with edit_posts) on sites that have been upgraded prior to 3.1.10 to restore the original privilege boundary.

Generated by OpenCVE AI on October 10, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. On fresh installations of version 3.1.10 and later, exploitation requires administrator-level access; however, on sites upgraded from a version prior to 3.1.10, the preserveCampaignRoleAccess() migration grants the edit_fireboxes capability to any role that previously held edit_posts, reducing the minimum required privilege to Author-level.
Title FireBox <= 3.1.13 - Authenticated (Author+) SQL Injection via FireBox Form Display Condition
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:47.567Z

Reserved: 2026-10-02T11:45:17.221Z

Link: CVE-2026-104724

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:39.627

Modified: 2026-10-10T05:16:39.627

Link: CVE-2026-104724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:00:12Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')