SQL Injection Vulnerability in FireBox Plugin for WordPress
CVE-2026-104724
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104724?
The FireBox β WooCommerce Popup Builder plugin for WordPress is susceptible to SQL Injection attacks through the FireBox Form Display Condition feature. This vulnerability arises from insufficient parameter escaping and inadequate SQL query preparation, enabling authenticated attackers with author-level access or higher to inject additional SQL queries. As a result, attackers can exploit this flaw to extract sensitive information from the database. Notably, if the plugin is upgraded from a version prior to 3.1.10, the migration process grants elevated privileges to user roles, significantly lowering the access level required to execute these malicious queries.
Affected Version(s)
FireBox β WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment 0 <= 3.1.13