Sceawere
Vulnerability Detail
CVE-2026-104724UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FireBox SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- fireplugins
- Product
- FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. On fresh installations of version 3.1.10 and later, exploitation requires administrator-level access; however, on sites upgraded from a version prior to 3.1.10, the preserveCampaignRoleAccess() migration grants the edit_fireboxes capability to any role that previously held edit_posts, reducing the minimum required privilege to Author-level.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-10T05:16:39.627Z",
"pubdate": "2026-10-10T05:16:39.627Z",
"executiveSummary": "The FireBox – WooCommerce Popup Builder plugin for WordPress is susceptible to a SQL Injection (SQLi) vulnerability, classified as a critical security flaw.\nThis vulnerability exists within the FireBox Form Display Condition functionality, where insufficient input sanitization and lack of parameterized queries allow for arbitrary SQL command execution.\nImpact includes the unauthorized extraction of sensitive database information, potentially leading to full site compromise or data breaches.\nThe vulnerability affects all versions up to and including 3.1.13.\nExploitation requirements vary based on installation history: while fresh installations of version 3.1.10 and later necessitate administrative privileges, legacy sites upgraded from earlier versions are vulnerable to attackers with author-level access due to the preserveCampaignRoleAccess() migration function.\nThis flaw presents a significant risk to the confidentiality and integrity of the affected WordPress site's database.",
"technicalDetails": "The root cause of this vulnerability is improper handling of user-supplied input within the FireBox Form Display Condition logic. The application fails to adequately escape input parameters before incorporating them into SQL queries, nor does it utilize prepared statements to isolate query logic from data input.\nThe vulnerability allows an authenticated attacker to perform SQL injection by injecting malicious SQL fragments into the display condition parameters. Because the database engine processes these injected statements as part of the primary query, the attacker can manipulate the query structure, bypass logical filters, and execute unauthorized database operations.\nThe attack flow involves an authenticated user crafting a malicious request targeting the FireBox settings where display conditions are defined. By embedding SQL syntax into these parameters, the attacker forces the backend to evaluate the injected commands. This leads to the execution of stacked or UNION-based queries, allowing the retrieval of arbitrary table content, including sensitive user information, configuration data, or authentication credentials.\nThe scope of the impact is exacerbated by the preserveCampaignRoleAccess() migration function present in versions 3.1.10 and later. This function inadvertently propagates the 'edit_fireboxes' capability to any user role that previously held 'edit_posts' permissions during an upgrade from a version prior to 3.1.10. Consequently, users with author-level access—who might not normally possess high-level administrative permissions—are granted the necessary privileges to execute the malicious queries. In fresh installations, however, the vulnerability remains restricted to administrative users.\nTechnical exploitation typically involves identifying the specific request handled by the display condition mechanism and analyzing the corresponding database interaction. An attacker can leverage tools to automate the extraction of data once the injection vector is verified. The post-exploitation impact ranges from unauthorized data exfiltration to the modification of existing entries, potentially allowing for privilege escalation if session tables or user roles are exposed through the injection."
}