← WordPress Vulnerabilities
WordPress security by component

Orbit Fox by ThemeIsle

Orbit Fox by ThemeIsle is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: themeisle-companion

CVE-2026-65563: Orbit Fox author input permits cross-site scripting

Orbit Fox through 3.0.7 lets an Author supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, field, parameter or rendering function.

PublishedJul 27, 2026
Known safe version3.0.8
Safe version
Jul 27, 2026 CVE-2026-65563
Orbit Fox author input permits cross-site scripting
Orbit Fox through 3.0.7 lets an Author supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, field, parameter or rendering function.
3.0.8
CVE5.9
NVDPending
Jun 18, 2026 CVE-2026-11358
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More: Cross-site scripting
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.0.6.
> 3.0.6
CVE4.4
NVDPending
Nov 04, 2025 CVE-2025-12045
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More: Cross-site scripting
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Sep 03, 2025 CVE-2025-58593
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jan 10, 2025 CVE-2024-13183
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 10, 2025 CVE-2025-0311
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 22, 2024 CVE-2024-7778
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 22, 2024 CVE-2024-2484
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1499
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1497
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 05, 2024 CVE-2024-0508
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 11, 2024 CVE-2023-6781
Orbit Fox by ThemeIsle: Cross-site scripting
Orbit Fox by ThemeIsle is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4