Junglewise Threat Intelligence

CVE-2026-12120: FirePlugins FireBox Popups sensitive information exposure via form_id

CVE-2026-12120 · Severity: medium · CVSS 5.3 · Published 2026-06-18

Executive brief

A popular WordPress plugin used for creating marketing popups and email subscription forms contains a security flaw. This vulnerability allows unauthorized individuals to download a full list of all information submitted through these forms, including names and email addresses. This could lead to the exposure of customer data and potential privacy violations.

Technical details

The FireBox Popups plugin for WordPress is vulnerable to sensitive information exposure (CWE-200) due to insufficient access control on form export functionality. By manipulating the 'form_id' parameter, an unauthenticated remote attacker can trigger a full CSV export of all submissions for any specific form. This data typically includes personally identifiable information (PII) provided by users during form submission. The vulnerability exists in all versions up to and including 3.1.7. A patch has been released in subsequent versions to restrict access to these exports.

Affected products

  • fireplugins FireBox Popups – Increase Sales and Grow Your Email List up to, and including, 3.1.7

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory

References