SQL Injection Vulnerability in FireBox Plugin for WordPress
CVE-2026-104724

5.3MEDIUM

What is CVE-2026-104724?

The FireBox – WooCommerce Popup Builder plugin for WordPress is susceptible to SQL Injection attacks through the FireBox Form Display Condition feature. This vulnerability arises from insufficient parameter escaping and inadequate SQL query preparation, enabling authenticated attackers with author-level access or higher to inject additional SQL queries. As a result, attackers can exploit this flaw to extract sensitive information from the database. Notably, if the plugin is upgraded from a version prior to 3.1.10, the migration process grants elevated privileges to user roles, significantly lowering the access level required to execute these malicious queries.

Affected Version(s)

FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment 0 <= 3.1.13

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.