PT-2026-50631 · WordPress · Firebox Popups
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FireBox Popups – Increase Sales and Grow Your Email List versions prior to 3.1.8
Description
The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress contains an issue allowing unauthenticated attackers to download a full CSV export of all form submissions. This exposure includes personally identifiable information submitted by users and is triggered via the
form id parameter.Recommendations
Update the plugin to a version later than 3.1.7.
Avoid using the
form id parameter in requests until the update is applied.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firebox Popups