Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the WordPress plugin developed by the vendor Orbit Fox, specifically covering features such as duplicate page functionality, menu icons, SVG support, cookie notices, and custom fonts integration. It aggregates data regarding weakness types including cross-site scripting, insecure direct object references, and insufficient security configuration that may arise from improper input handling or default settings within these specific modules. The collection spans from the initial release of the plugin up to the most recent security advisories issued by the vendor or discovered by independent security researchers, ensuring a comprehensive historical view of identified flaws. Visitors can utilize this resource to track a vendor's response to reported issues, understand the implications of specific weakness classes in the context of WordPress plugins, or look up a product's vulnerability history to assess long-term maintenance practices. This information supports developers and site administrators in evaluating the security posture of the Orbit Fox suite, identifying potential risks before deployment, and prioritizing updates based on the severity and exploitability of known vulnerabilities. The page serves as a centralized reference for understanding how specific feature sets have been historically affected by security breaches, facilitating more informed decision-making regarding plugin usage and security hygiene in WordPress environments.

Vendor: themeisle

CVE IDTitleCVSSSeverityPublished
CVE-2025-12045 Orbit Fox Companion <= 3.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post Taxonomy CWE-79 6.4 Medium2025-11-04
CVE-2025-10874 Orbit Fox < 3.0.2 - Author+ Server-Side Request Forgery 8.2 -2025-10-24
CVE-2024-13183 Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag Parameter CWE-79 6.4 Medium2025-01-10
CVE-2025-0311 Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget CWE-79 6.4 Medium2025-01-10
CVE-2024-7778 Orbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CWE-79 6.4 Medium2024-08-22
CVE-2024-2484 Orbit Fox by ThemeIsle <= 2.10.34 - Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets CWE-79 6.4 Medium2024-06-22
CVE-2024-1499 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-13
CVE-2024-1497 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via form widget addr2_width attribute CWE-79 6.4 Medium2024-03-13
CVE-2024-2126 Orbit Fox by ThemeIsle <= 2.10.32 - Authenticated (Contributor+) Stored Cross-Site Scripiting via Registration Form Widget CWE-79 6.4 Medium2024-03-13
CVE-2024-1323 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-27
CVE-2024-0508 Orbit Fox by ThemeIsle <= 2.10.27 - Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget CWE-79 6.4 Medium2024-02-05
CVE-2024-1162 Orbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request Forgery CWE-352 4.3 Medium2024-02-02
CVE-2023-6781 Orbit Fox Companion <= 2.10.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via custom fields CWE-20 6.4 Medium2024-01-11

All 13 known CVE vulnerabilities affecting Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More with full Chinese analysis, references, and POCs where available.