Impact
The Orbit Fox plugin for WordPress allows users with the upload capability to upload SVG files. Since versions before 3.0.8 do not sanitize SVG content, an authenticated Author or higher can embed JavaScript in an SVG. When the file is viewed, the script runs in the site context, giving the attacker the ability to steal cookies, deface the site, or perform further attacks. This stored cross‑site scripting flaw therefore directly compromises the confidentiality, integrity, and availability of the affected WordPress installation.
Affected Systems
The vulnerability impacts the Orbit Fox plugin (known as Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More) from ThemeIsle, in all releases prior to 3.0.8. Sites running these versions with the SVG upload feature enabled and with Authors or higher able to upload files are exposed. All authenticated users who can upload media are potential vectors for exploitation.
Risk and Exploitability
While the EPSS score is currently unavailable and the vulnerability is not listed in CISA's KEV catalog, the CVSS base score is not provided, yet the presence of stored cross‑site scripting indicates a high severity. The attack requires legitimate credentials with upload rights but does not need the unfiltered_html capability. Without a patch or remediation, the risk of exploitation remains significant and should be treated as high.
OpenCVE Enrichment