PT-2026-67978 · WordPress · Orbit Fox
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin versions prior to 3.0.8
Description
The plugin fails to sanitize uploaded SVG files when the SVG upload feature is enabled. This allows authenticated users with upload capabilities (such as Author and above) to upload SVG files containing JavaScript. When these files are viewed, the script executes within the site context, resulting in Stored Cross-Site Scripting (XSS), a flaw where malicious scripts are permanently stored on the target server.
Recommendations
Update the plugin to version 3.0.8 or later.
As a temporary mitigation, disable the SVG upload feature.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Orbit Fox