Cross-Site Scripting in Orbit Fox Plugin for WordPress
CVE-2026-85418
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
Badges
What is CVE-2026-85418?
The Orbit Fox plugin for WordPress, prior to version 3.0.9, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw arises from inadequate validation of user-supplied HTML tag names within specific Beaver Builder widgets. As a result, users possessing contributor-level access or higher can inject arbitrary scripts. These scripts execute when visitors load the affected pages, potentially compromising user data and website security. It is crucial for website administrators to upgrade to the latest version to mitigate these security risks.
Affected Version(s)
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More 0 < 3.0.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.