Impact
A stored cross‑site scripting flaw is present in the Orbit Fox WordPress plugin for versions before 3.0.9. The flaw stems from the plugin’s failure to validate a user‑supplied HTML tag name used in one of its Beaver Builder widgets before echoing it into the page markup. Users who have contributor or higher privileges can insert arbitrary JavaScript into that widget; the script then executes in the browser of any visitor who loads the affected page. The vulnerability enables client‑side code execution but no specific downstream effects are mentioned in the official description. Typical downstream effects such as data exfiltration are inferred from the nature of the vulnerability but are not explicitly detailed in the CVE description.
Affected Systems
WordPress sites that have the Orbit Fox plugin (Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More) installed and running a version earlier than 3.0.9 are impacted. No other plug‑in versions or WordPress core components are affected by this issue.
Risk and Exploitability
The vulnerability requires that an attacker possess contributor‑level or higher access. The CVE description does not specify how that access is obtained; it is reasonable to infer that credential compromise, social engineering, or privilege escalation would be required. Once the malicious payload is embedded, it executes on every visitor’s browser, creating a broad attack surface. The CVSS score of 5.4 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation. The issue is not listed in the CISA KEV catalog. The likely attack vector is the injection of malicious script through a Beaver Builder widget that is rendered for all site visitors.
OpenCVE Enrichment