Stored Cross-site Scripting Vulnerability in Themeisle Orbit Fox Plugin
CVE-2025-58593

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2025

What is CVE-2025-58593?

The Orbit Fox plugin by ThemeIsle is susceptible to a stored Cross-site Scripting (XSS) vulnerability, allowing an attacker to inject malicious scripts that can be executed in the context of the user’s browser. This can lead to unauthorized actions being performed on behalf of the user, potentially compromising sensitive data and website integrity. Users of Orbit Fox versions up to 3.0.0 should investigate and apply necessary updates to safeguard against exploitation.

Affected Version(s)

Orbit Fox by ThemeIsle <= 3.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael (Patchstack Alliance)
.