Cross-Site Scripting in Orbit Fox Plugin for WordPress
CVE-2026-85418

Currently unrated

Key Information:

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-85418?

The Orbit Fox plugin for WordPress, prior to version 3.0.9, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw arises from inadequate validation of user-supplied HTML tag names within specific Beaver Builder widgets. As a result, users possessing contributor-level access or higher can inject arbitrary scripts. These scripts execute when visitors load the affected pages, potentially compromising user data and website security. It is crucial for website administrators to upgrade to the latest version to mitigate these security risks.

Affected Version(s)

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More 0 < 3.0.9

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Farid Narimanov
WPScan
.