Extension WordPress
Vulnérabilités Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
Cette page rassemble les failles publiées pour Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
21 fiches
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' Parameter
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.6 due to insufficient…
*-3.0.6
3.0.7
17/06/2026
Orbit Fox Companion <= 3.0.2 – Authenticated (Author+) Stored Cross-Site Scripting via Post Taxonomy
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the category and tag 'name' parameters in all versions up to, and including,…
*-3.0.2
3.0.3
03/11/2025
Orbit Fox by ThemeIsle <= 3.0.1 – Authenticated (Author+) Server-Side Request Forgery
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.1. This makes it possible for authenticated…
*-3.0.1
3.0.2
03/10/2025
Orbit Fox by ThemeIsle <= 3.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-3.0.0
3.0.1
03/09/2025
Orbit Fox by ThemeIsle <= 2.10.44 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-2.10.44
2.10.45
03/02/2025
Orbit Fox by ThemeIsle <= 2.10.43 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag Parameter
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping. This makes it possible…
*-2.10.43
2.10.44
09/01/2025
Orbit Fox by ThemeIsle <= 2.10.43 – Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping on user…
*-2.10.43
2.10.44
09/01/2025
Orbit Fox by ThemeIsle <= 2.10.36 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.10.36 due to insufficient input sanitization and output escaping. This makes it possible…
*-2.10.36
2.10.37
21/08/2024
Orbit Fox by ThemeIsle <= 2.10.34 – Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versions up to, and including, 2.10.34 due to insufficient input sanitization and output escaping.…
*-2.10.34
2.10.35
21/06/2024
Orbit Fox by ThemeIsle <= 2.10.32 – Authenticated (Contributor+) Stored Cross-Site Scripiting via Registration Form Widget
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form widget in all versions up to, and including, 2.10.32 due to insufficient input sanitization and output escaping. This makes it…
*-2.10.32
2.10.33
07/03/2024
Orbit Fox by ThemeIsle <= 2.10.30 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in the $settings['title_tags'] parameter in all versions up to, and including, 2.10.30 due to insufficient input sanitization and output…
*-2.10.30
2.10.31
26/02/2024
Orbit Fox by ThemeIsle <= 2.10.30 – Authenticated (Contributor+) Stored Cross-Site Scripting via form widget addr2_width attribute
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_width attribute in all versions up to, and including, 2.10.30 due to insufficient input sanitization and output escaping. This makes…
*-2.10.30
2.10.31
26/02/2024
Orbit Fox by ThemeIsle <= 2.10.30 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all versions up to, and including, 2.10.30 due to insufficient input sanitization and output escaping…
*-2.10.31
2.10.32
26/02/2024
ThemeIsle SDK <= Various Versions – Missing Authorization
Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to…
*-2.10.28
2.10.29
01/02/2024
Orbit Fox by ThemeIsle <= 2.10.29 – Cross-Site Request Forgery
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due to missing or incorrect nonce validation on the register_reference() function. This makes it…
*-2.10.29
2.10.230
01/02/2024
Orbit Fox by ThemeIsle <= 2.10.27 – Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all versions up to, and including, 2.10.27 due to insufficient input sanitization and output escaping on…
*-2.10.27
2.10.28
15/01/2024
Orbit Fox Companion <= 2.10.26 – Authenticated (Contributor+) Stored Cross-Site Scripting via custom fields
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 2.10.26 due to insufficient input sanitization and output escaping on user supplied…
*-2.10.26
2.10.27
05/01/2024
Orbit Fox by ThemeIsle <= 2.10.23 – Authenticated (Author+) Server-Side Request Forgery via URL
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.10.23 via the parse_request function. This can allow authenticated attackers with the upload_files capability, like authors and above,…
[*, 2.10.24)
2.10.24
27/04/2023
Orbit Fox by ThemeIsle <= 2.10.2 – Authenticated (Contributor+) Stored Cross Site Scripting
Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the…
[*, 2.10.3)
2.10.3
12/01/2021
Orbit Fox by ThemeIsle <= 2.10.2 – Authenticated Privilege Escalation
Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default…
[*, 2.10.3)
2.10.3
24/11/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.