Stored Cross-Site Scripting in Orbit Fox Plugin for WordPress
CVE-2026-16583
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
Badges
What is CVE-2026-16583?
The Orbit Fox WordPress plugin versions prior to 3.0.8 have a significant vulnerability that permits authenticated users to upload SVG files without proper sanitization. This lack of validation can lead to the injection of JavaScript code that executes within the site's context when the malicious SVG file is accessed. As a result, this vulnerability can enable attackers to execute harmful scripts, manipulate site content, and potentially compromise user data. It is crucial for users of the Orbit Fox plugin to update to the latest version to mitigate this risk.
Affected Version(s)
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More 3.0.0 < 3.0.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.