WordPress · Orbit Fox · CVE-2026-16583
**Name of the Vulnerable Software and Affected Versions**
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin versions prior to 3.0.8
**Description**
The plugin fails to sanitize uploaded SVG files when the SVG upload feature is enabled. This allows authenticated users with upload capabilities (such as Author and above) to upload SVG files containing JavaScript. When these files are viewed, the script executes within the site context, resulting in Stored Cross-Site Scripting (XSS), a flaw where malicious scripts are permanently stored on the target server.
**Recommendations**
Update the plugin to version 3.0.8 or later.
As a temporary mitigation, disable the SVG upload feature.