Description
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfiltered_html capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Orbit Fox plugin for WordPress allows users with the upload capability to upload SVG files. Since versions before 3.0.8 do not sanitize SVG content, an authenticated Author or higher can embed JavaScript in an SVG. When the file is viewed, the script runs in the site context, giving the attacker the ability to steal cookies, deface the site, or perform further attacks. This stored cross‑site scripting flaw therefore directly compromises the confidentiality, integrity, and availability of the affected WordPress installation.

Affected Systems

The vulnerability impacts the Orbit Fox plugin (known as Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More) from ThemeIsle, in all releases prior to 3.0.8. Sites running these versions with the SVG upload feature enabled and with Authors or higher able to upload files are exposed. All authenticated users who can upload media are potential vectors for exploitation.

Risk and Exploitability

While the EPSS score is currently unavailable and the vulnerability is not listed in CISA's KEV catalog, the CVSS base score is not provided, yet the presence of stored cross‑site scripting indicates a high severity. The attack requires legitimate credentials with upload rights but does not need the unfiltered_html capability. Without a patch or remediation, the risk of exploitation remains significant and should be treated as high.

Generated by OpenCVE AI on August 5, 2026 at 07:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Orbit Fox update (3.0.8 or newer) to remove the unsanitized SVG upload flaw.
  • If an update is not immediately possible, disable the SVG upload feature or delete existing SVG files from the media library.
  • Restrict the upload capability so that only trusted administrators can upload media, or remove the upload role for non‑admin users.
  • Audit media libraries for any embedded SVG files containing suspicious JavaScript and delete them.

Generated by OpenCVE AI on August 5, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfiltered_html capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting.
Title Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T06:00:09.233Z

Reserved: 2026-07-22T13:41:53.741Z

Link: CVE-2026-16583

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T07:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')