Stored Cross-Site Scripting in Orbit Fox Plugin for WordPress
CVE-2026-11358

4.4MEDIUM

What is CVE-2026-11358?

The Orbit Fox plugin for WordPress contains a vulnerability that allows authenticated administrators to inject arbitrary web scripts through insufficient input sanitization in admin settings. This vulnerability is particularly concerning for multi-site installations and those where unfiltered_html is disabled, as it enables the execution of scripts whenever an injected page is accessed. This threat emphasizes the importance of proper sanitization and escaping mechanisms to protect web applications from exploitative attacks.

Affected Version(s)

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More 0 <= 3.0.6

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Meher Sudhakar Abbireddi
.