WordPress security by component
Orbit Fox by ThemeIsle
Plugin description
Orbit Fox by ThemeIsle is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.
Plugin slug:
themeisle-companionLatest vulnerability
CVE-2026-65563: Orbit Fox author input permits cross-site scripting
Orbit Fox through 3.0.7 lets an Author supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, field, parameter or rendering function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-65563
Orbit Fox author input permits cross-site scripting
Orbit Fox through 3.0.7 lets an Author supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, field, parameter or rendering function.
|
3.0.8 |
CVE5.9
NVDPending
|
| Jun 18, 2026 |
CVE-2026-11358
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More: Cross-site scripting
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.0.6.
|
> 3.0.6 |
CVE4.4
NVDPending
|
| Nov 04, 2025 |
CVE-2025-12045
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More: Cross-site scripting
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Sep 03, 2025 |
CVE-2025-58593
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 10, 2025 |
CVE-2024-13183
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 10, 2025 |
CVE-2025-0311
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Aug 22, 2024 |
CVE-2024-7778
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 22, 2024 |
CVE-2024-2484
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1499
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1497
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 05, 2024 |
CVE-2024-0508
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 11, 2024 |
CVE-2023-6781
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|