Stored Cross-Site Scripting in Orbit Fox Plugin for WordPress
CVE-2026-11358
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 June 2026
What is CVE-2026-11358?
The Orbit Fox plugin for WordPress contains a vulnerability that allows authenticated administrators to inject arbitrary web scripts through insufficient input sanitization in admin settings. This vulnerability is particularly concerning for multi-site installations and those where unfiltered_html is disabled, as it enables the execution of scripts whenever an injected page is accessed. This threat emphasizes the importance of proper sanitization and escaping mechanisms to protect web applications from exploitative attacks.
Affected Version(s)
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More 0 <= 3.0.6