PT-2026-67978 · WordPress · Orbit Fox

·

CVE-2026-16583

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin versions prior to 3.0.8
Description The plugin fails to sanitize uploaded SVG files when the SVG upload feature is enabled. This allows authenticated users with upload capabilities (such as Author and above) to upload SVG files containing JavaScript. When these files are viewed, the script executes within the site context, resulting in Stored Cross-Site Scripting (XSS), a flaw where malicious scripts are permanently stored on the target server.
Recommendations Update the plugin to version 3.0.8 or later. As a temporary mitigation, disable the SVG upload feature.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16583

Affected Products

Orbit Fox