Sceawere

Vulnerability Detail

CVE-2026-104724UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FireBox SQL Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
fireplugins
Product
FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. On fresh installations of version 3.1.10 and later, exploitation requires administrator-level access; however, on sites upgraded from a version prior to 3.1.10, the preserveCampaignRoleAccess() migration grants the edit_fireboxes capability to any role that previously held edit_posts, reducing the minimum required privilege to Author-level.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-10T05:16:39.627Z",
  "pubdate": "2026-10-10T05:16:39.627Z",
  "executiveSummary": "The FireBox – WooCommerce Popup Builder plugin for WordPress is susceptible to a SQL Injection (SQLi) vulnerability, classified as a critical security flaw.\nThis vulnerability exists within the FireBox Form Display Condition functionality, where insufficient input sanitization and lack of parameterized queries allow for arbitrary SQL command execution.\nImpact includes the unauthorized extraction of sensitive database information, potentially leading to full site compromise or data breaches.\nThe vulnerability affects all versions up to and including 3.1.13.\nExploitation requirements vary based on installation history: while fresh installations of version 3.1.10 and later necessitate administrative privileges, legacy sites upgraded from earlier versions are vulnerable to attackers with author-level access due to the preserveCampaignRoleAccess() migration function.\nThis flaw presents a significant risk to the confidentiality and integrity of the affected WordPress site's database.",
  "technicalDetails": "The root cause of this vulnerability is improper handling of user-supplied input within the FireBox Form Display Condition logic. The application fails to adequately escape input parameters before incorporating them into SQL queries, nor does it utilize prepared statements to isolate query logic from data input.\nThe vulnerability allows an authenticated attacker to perform SQL injection by injecting malicious SQL fragments into the display condition parameters. Because the database engine processes these injected statements as part of the primary query, the attacker can manipulate the query structure, bypass logical filters, and execute unauthorized database operations.\nThe attack flow involves an authenticated user crafting a malicious request targeting the FireBox settings where display conditions are defined. By embedding SQL syntax into these parameters, the attacker forces the backend to evaluate the injected commands. This leads to the execution of stacked or UNION-based queries, allowing the retrieval of arbitrary table content, including sensitive user information, configuration data, or authentication credentials.\nThe scope of the impact is exacerbated by the preserveCampaignRoleAccess() migration function present in versions 3.1.10 and later. This function inadvertently propagates the 'edit_fireboxes' capability to any user role that previously held 'edit_posts' permissions during an upgrade from a version prior to 3.1.10. Consequently, users with author-level access—who might not normally possess high-level administrative permissions—are granted the necessary privileges to execute the malicious queries. In fresh installations, however, the vulnerability remains restricted to administrative users.\nTechnical exploitation typically involves identifying the specific request handled by the display condition mechanism and analyzing the corresponding database interaction. An attacker can leverage tools to automate the extraction of data once the injection vector is verified. The post-exploitation impact ranges from unauthorized data exfiltration to the modification of existing entries, potentially allowing for privilege escalation if session tables or user roles are exposed through the injection."
}
CVE-2026-104724: FireBox SQL Injection Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere