Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More, with AI-generated Chinese analysis, references, and POCs.

This page catalogs security weaknesses associated with the Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin, categorized under its specific vendor and product identifiers. It aggregates known vulnerabilities discovered in this WordPress extension, covering security incidents reported from its initial release through recent updates. Here, researchers and administrators can track the vendor’s historical security advisories to understand how issues were communicated and resolved over time. Users can also analyze trends within specific weakness classes to identify recurring architectural flaws or coding errors typical of this type of plugin. By examining the full vulnerability history, stakeholders gain insight into the product’s security posture and the effectiveness of its maintenance practices. This resource serves as a centralized reference for evaluating risk exposure related to this specific software component. It is designed to help developers, site owners, and security analysts assess the impact of known flaws without needing to search through disparate sources. The data presented allows for a comprehensive view of past security breaches, configuration errors, and logic flaws that have been publicly disclosed. This aggregation facilitates better informed decision-making regarding plugin selection, update priorities, and defensive coding strategies. Understanding the context of these weaknesses helps in implementing appropriate mitigations and staying compliant with security best practices. The page does not contain speculative data or unverified reports, ensuring that the information remains reliable and actionable for professionals managing WordPress infrastructure.

Vendor: themeisle

CVE IDTitleCVSSSeverityPublished
CVE-2026-11358 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' Parameter CWE-79 4.4 Medium2026-06-18
CVE-2025-12045 Orbit Fox Companion <= 3.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post Taxonomy CWE-79 6.4 Medium2025-11-04
CVE-2025-10874 Orbit Fox < 3.0.2 - Author+ Server-Side Request Forgery 8.2 -2025-10-24
CVE-2024-13183 Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag Parameter CWE-79 6.4 Medium2025-01-10
CVE-2025-0311 Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget CWE-79 6.4 Medium2025-01-10
CVE-2024-7778 Orbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CWE-79 6.4 Medium2024-08-22
CVE-2024-2484 Orbit Fox by ThemeIsle <= 2.10.34 - Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets CWE-79 6.4 Medium2024-06-22
CVE-2024-1499 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-13
CVE-2024-1497 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via form widget addr2_width attribute CWE-79 6.4 Medium2024-03-13
CVE-2024-2126 Orbit Fox by ThemeIsle <= 2.10.32 - Authenticated (Contributor+) Stored Cross-Site Scripiting via Registration Form Widget CWE-79 6.4 Medium2024-03-13
CVE-2024-1323 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-27
CVE-2024-0508 Orbit Fox by ThemeIsle <= 2.10.27 - Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget CWE-79 6.4 Medium2024-02-05
CVE-2024-1162 Orbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request Forgery CWE-352 4.3 Medium2024-02-02
CVE-2023-6781 Orbit Fox Companion <= 2.10.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via custom fields CWE-20 6.4 Medium2024-01-11

All 14 known CVE vulnerabilities affecting Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More with full Chinese analysis, references, and POCs where available.