Browse all 4 CVE security advisories affecting FirePlugins. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-104724 | FireBox <= 3.1.13 - Authenticated (Author+) SQL Injection via FireBox Form Display Condition — FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment CWE-89 | 5.3 | Medium | 2026-10-10 |
| CVE-2026-76801 | FireBox <= 3.1.10 - Authenticated (Author+) Remote Code Execution to Privilege Escalation — FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment CWE-269 | 8.8 | High | 2026-09-09 |
| CVE-2026-12120 | FireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' Parameter — FireBox Popups – Increase Sales and Grow Your Email List CWE-200 | 5.3 | Medium | 2026-06-18 |
| CVE-2025-67545 | WordPress FireBox plugin <= 3.1.0-free - Cross Site Scripting (XSS) vulnerability — FireBox CWE-79 | 6.5 | Medium | 2025-12-09 |
This page lists every published CVE security advisory associated with FirePlugins. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.