Description
The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.7 via the 'form_id' parameter. This makes it possible for unauthenticated attackers to extract download a full CSV export of all form submissions — including any personally identifiable information submitted by users — for any arbitrary form_id.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fireplugins
Fireplugins firebox Popups – Increase Sales And Grow Your Email List Wordpress Wordpress wordpress |
|
| Vendors & Products |
Fireplugins
Fireplugins firebox Popups – Increase Sales And Grow Your Email List Wordpress Wordpress wordpress |
Thu, 18 Jun 2026 16:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-18T12:44:12.103Z
Reserved: 2026-06-12T15:02:04.475Z
Link: CVE-2026-12120
Updated: 2026-06-18T12:44:05.524Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:56:43Z
Weaknesses