Vulnerabilities > Themeisle > Orbit FOX

DATE CVE VULNERABILITY TITLE RISK
2024-08-22 CVE-2024-7778 Cross-site Scripting vulnerability in Themeisle Orbit FOX
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.10.36 due to insufficient input sanitization and output escaping.
network
low complexity
themeisle CWE-79
5.4
2024-06-22 CVE-2024-2484 Cross-site Scripting vulnerability in Themeisle Orbit FOX
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versions up to, and including, 2.10.34 due to insufficient input sanitization and output escaping.
network
low complexity
themeisle CWE-79
5.4
2024-02-05 CVE-2024-0508 Cross-site Scripting vulnerability in Themeisle Orbit FOX
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all versions up to, and including, 2.10.27 due to insufficient input sanitization and output escaping on the user supplied link URL.
network
low complexity
themeisle CWE-79
5.4
2024-02-02 CVE-2024-1047 Missing Authorization vulnerability in Themeisle Orbit FOX
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in all versions up to, and including, 2.10.28.
network
low complexity
themeisle CWE-862
5.3
2024-02-02 CVE-2024-1162 Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Orbit FOX
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29.
network
low complexity
themeisle CWE-352
4.3
2024-01-11 CVE-2023-6781 Cross-site Scripting vulnerability in Themeisle Orbit FOX
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 2.10.26 due to insufficient input sanitization and output escaping on user supplied values.
network
low complexity
themeisle CWE-79
5.4
2021-04-05 CVE-2021-24158 Unspecified vulnerability in Themeisle Orbit FOX
Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality.
network
themeisle
3.5
2021-04-05 CVE-2021-24157 Cross-site Scripting vulnerability in Themeisle Orbit FOX
Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post.
network
themeisle CWE-79
3.5