Impact
The Orbit Fox plugin contains a stored cross‑site scripting flaw that allows an administrator to encode arbitrary JavaScript in the 'menu-item‑icon' setting. When a page containing the injected icon is displayed, all visitors run the embedded script, leading to potential session theft, defacement, or data exfiltration. The flaw is caused by insufficient input filtering and lack of escaping when saving the icon path. The vulnerability can only be exercised by users with admin‑level access and is only present when the WordPress multi‑site feature is enabled and the unfiltered_html capability is disabled, ensuring that only trusted administrators can use the feature.
Affected Systems
WordPress sites using the Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin, versions 3.0.6 and earlier, especially in multisite deployments. The vendor, themeisle, has identified the flaw in all versions up to 3.0.6. Sites that have upgraded to 3.0.7 or later are not affected.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and the EPSS score of <1% shows that exploitation is considered unlikely at this time. It is not listed in the CISA KEV catalog. The exploit requires an authenticated administrator within a multisite WordPress environment, so it does not affect anonymous users. Attackers could leverage the stored script to hijack legitimate sessions, redirect users, or serve malware, but only after gaining the necessary administrative privileges.
OpenCVE Enrichment