Themeisle
Themeisle Orbit FOX: vulnerabilidades y CVE
Themeisle Orbit FOX tiene 21 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85418 | Media (5.4) | 0.23% | — | 9 sept 2026 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9 does not validate a user-supplied HTML tag name in one of its Beaver Builder widgets before… |
| CVE-2026-16583 | Media (6.1) | 0.25% | — | 5 ago 2026 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing… |
| CVE-2026-65563 | Media (5.9) | 0.24% | — | 27 jul 2026 | Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. |
| CVE-2026-11358 | Media (4.4) | 0.26% | — | 18 jun 2026 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.6… |
| CVE-2025-10874 | Media (5.5) | 0.19% | — | 24 oct 2025 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be used for the stock photo import feature, allowing the user to… |
| CVE-2025-58593 | Media (6.5) | 0.21% | — | 3 sept 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle themeisle-companion allows Stored XSS.This issue affects Orbit Fox by ThemeIsle:… |
| CVE-2025-22659 | Media (5.4) | 0.29% | — | 27 mar 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle themeisle-companion allows Stored XSS.This issue affects Orbit Fox by ThemeIsle:… |
| CVE-2024-13183 | Media (5.4) | 0.49% | — | 10 ene 2025 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output… |
| CVE-2025-0311 | Media (5.4) | 0.35% | — | 10 ene 2025 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient input sanitization and… |
| CVE-2024-7778 | Media (5.4) | 0.33% | — | 22 ago 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.10.36 due to insufficient input sanitization and output escaping.… |
| CVE-2024-2484 | Media (5.4) | 0.39% | — | 22 jun 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versions up to, and including, 2.10.34 due to insufficient input… |
| CVE-2024-2126 | Media (5.4) | 0.42% | — | 13 mar 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form widget in all versions up to, and including, 2.10.32 due to insufficient input sanitization and… |
| CVE-2024-1499 | Media (5.4) | 0.53% | — | 13 mar 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in the $settings['title_tags'] parameter in all versions up to, and including, 2.10.30 due to… |
| CVE-2024-1497 | Media (5.4) | 0.53% | — | 13 mar 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_width attribute in all versions up to, and including, 2.10.30 due to insufficient input sanitization… |
| CVE-2024-1323 | Media (5.4) | 0.49% | — | 27 feb 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all versions up to, and including, 2.10.30 due to insufficient input… |
| CVE-2024-0508 | Media (5.4) | 0.52% | — | 5 feb 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all versions up to, and including, 2.10.27 due to insufficient input… |
| CVE-2024-1162 | Media (4.3) | 0.23% | — | 2 feb 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due to missing or incorrect nonce validation on the register_reference()… |
| CVE-2024-1047 | Media (5.3) | 0.56% | — | 2 feb 2024 | Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This… |
| CVE-2023-6781 | Media (5.4) | 0.40% | — | 11 ene 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 2.10.26 due to insufficient input sanitization and output… |
| CVE-2021-24158 | Media (6.5) | 0.90% | — | 5 abr 2021 | Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the… |
| CVE-2021-24157 | Media (5.4) | 0.69% | — | 5 abr 2021 | Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus… |