Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security advisories for Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More, focusing on a specific WordPress theme or plugin. It collects reported vulnerabilities across multiple weakness classes, covering a defined historical time range of disclosed issues. Readers can use this section to track the vendor's advisory history, understand the prevalence of specific vulnerability types, and review the cumulative vulnerability record for this product.

Vendor: themeisle

CVE ID Title CVSS Severity Published
CVE-2026-85418 Orbit Fox < 3.0.9 - Contributor+ Stored XSS via Beaver Builder Pricing Table Widget - - 2026-09-09
CVE-2026-16583 Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload - - 2026-08-05
CVE-2026-11358 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' Parameter CWE-79 4.4 Medium 2026-06-18
CVE-2025-12045 Orbit Fox Companion <= 3.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post Taxonomy CWE-79 6.4 Medium 2025-11-04
CVE-2025-10874 Orbit Fox < 3.0.2 - Author+ Server-Side Request Forgery 8.2 - 2025-10-24
CVE-2024-13183 Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag Parameter CWE-79 6.4 Medium 2025-01-10
CVE-2025-0311 Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget CWE-79 6.4 Medium 2025-01-10
CVE-2024-7778 Orbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CWE-79 6.4 Medium 2024-08-22
CVE-2024-2484 Orbit Fox by ThemeIsle <= 2.10.34 - Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets CWE-79 6.4 Medium 2024-06-22
CVE-2024-1499 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-03-13
CVE-2024-1497 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via form widget addr2_width attribute CWE-79 6.4 Medium 2024-03-13
CVE-2024-2126 Orbit Fox by ThemeIsle <= 2.10.32 - Authenticated (Contributor+) Stored Cross-Site Scripiting via Registration Form Widget CWE-79 6.4 Medium 2024-03-13
CVE-2024-1323 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-02-27
CVE-2024-0508 Orbit Fox by ThemeIsle <= 2.10.27 - Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget CWE-79 6.4 Medium 2024-02-05
CVE-2024-1162 Orbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request Forgery CWE-352 4.3 Medium 2024-02-02
CVE-2023-6781 Orbit Fox Companion <= 2.10.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via custom fields CWE-20 6.4 Medium 2024-01-11

All 16 known CVE vulnerabilities affecting Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More with full Chinese analysis, references, and POCs where available.