Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 6.1.
orbit-fox-duplicate-page-menu-icons-svg-support-cookie-notice-custom-fonts-moreCVE-2026-16583: Orbit Fox SVG uploads permit author-level stored XSS
Orbit Fox versions 3.0.0 through 3.0.7 do not sanitize SVG files when the plugin's SVG upload feature is enabled. A user with the upload_files capability, Author and above by default, can upload an SVG containing JavaScript even without unfiltered_html. The script executes in the WordPress site origin when a victim views the SVG and can target an administrator session. This unscored record received deeper review because the stored-XSS payload can reach administrators; the CNA does not disclose the upload endpoint or field name.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-16583
Orbit Fox SVG uploads permit author-level stored XSS
Orbit Fox versions 3.0.0 through 3.0.7 do not sanitize SVG files when the plugin's SVG upload feature is enabled. A user with the upload_files capability, Author and above by default, can upload an SVG containing JavaScript even without unfiltered_html. The script executes in the WordPress site origin when a victim views the SVG and can target an administrator session. This unscored record received deeper review because the stored-XSS payload can reach administrators; the CNA does not disclose the upload endpoint or field name.
|
3.0.8 |
CVE6.1
NVDPending
|
| Oct 24, 2025 |
CVE-2025-10874
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More: Server-side request forgery
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.5
NVDPending
|