The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the category and tag 'name' parameters in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themeisle
Themeisle orbit Fox Wordpress Wordpress wordpress |
|
| Vendors & Products |
Themeisle
Themeisle orbit Fox Wordpress Wordpress wordpress |
Tue, 04 Nov 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the category and tag 'name' parameters in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
| Title | Orbit Fox Companion <= 3.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post Taxonomy | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-04T11:19:27.966Z
Updated: 2025-11-04T18:53:30.602Z
Reserved: 2025-10-21T19:37:36.665Z
Link: CVE-2025-12045
Updated: 2025-11-04T18:53:24.675Z
Status : Awaiting Analysis
Published: 2025-11-04T12:15:35.960
Modified: 2025-11-04T15:40:45.533
Link: CVE-2025-12045
No data.