← WordPress Vulnerabilities
WordPress security by component

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 6.1.

Plugin slug: orbit-fox-duplicate-page-menu-icons-svg-support-cookie-notice-custom-fonts-more

CVE-2026-16583: Orbit Fox SVG uploads permit author-level stored XSS

Orbit Fox versions 3.0.0 through 3.0.7 do not sanitize SVG files when the plugin's SVG upload feature is enabled. A user with the upload_files capability, Author and above by default, can upload an SVG containing JavaScript even without unfiltered_html. The script executes in the WordPress site origin when a victim views the SVG and can target an administrator session. This unscored record received deeper review because the stored-XSS payload can reach administrators; the CNA does not disclose the upload endpoint or field name.

PublishedAug 05, 2026
Known safe version3.0.8
Published vulnerabilities for orbit-fox-duplicate-page-menu-icons-svg-support-cookie-notice-custom-fonts-more
Safe version
Aug 05, 2026 CVE-2026-16583
Orbit Fox SVG uploads permit author-level stored XSS
Orbit Fox versions 3.0.0 through 3.0.7 do not sanitize SVG files when the plugin's SVG upload feature is enabled. A user with the upload_files capability, Author and above by default, can upload an SVG containing JavaScript even without unfiltered_html. The script executes in the WordPress site origin when a victim views the SVG and can target an administrator session. This unscored record received deeper review because the stored-XSS payload can reach administrators; the CNA does not disclose the upload endpoint or field name.
3.0.8
CVE6.1
NVDPending
Oct 24, 2025 CVE-2025-10874
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More: Server-side request forgery
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.5
NVDPending