Impact
The vulnerability allows stored cross‑site scripting because input is not properly neutralised before being output within a page. This means malicious JavaScript can be stored in the plugin and executed when a visitor loads the affected content. The weakness is identified as CWE‑79.
Affected Systems
The flaw affects all installations of the Themeisle Orbit Fox by ThemeIsle plugin with versions up to and including 3.0.0. No other releases are affected according to the available data.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of <1 % suggests a low likelihood of widespread exploitation. The plugin is not listed in CISA’s KEV catalog. The vulnerability is caused by the plugin storing user input that is later displayed without proper neutralisation, enabling stored cross‑site scripting.
OpenCVE Enrichment
EUVD