CVE-2025-12045
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
Minimum safe version
3.0.3
Update to 3.0.3 or later to address 25 fixable vulnerabilities
CVE-2025-10874
CVE-2025-58593
CVE-2025-22659
CVE-2024-13183
WordPress Orbit Fox by ThemeIsle Plugin <= 2.10.43 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-7778
CVE-2024-2484
CVE-2024-2126
CVE-2024-1497
CVE-2024-1499
CVE-2024-1323
CVE-2024-1162
CVE-2024-1047
CVE-2024-0508
Orbit Fox by ThemeIsle <= 2.10.27 - Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget
CVE-2023-6781
Orbit Fox by ThemeIsle <= 2.6.3 -Does not properly Authenticate REST API Calls
CVE-2023-2287
WordPress Orbit Fox by ThemeIsle Plugin < 2.10.24 is vulnerable to Server Side Request Forgery (SSRF)
Orbit Fox by ThemeIsle <= 2.6.3 - Improper REST Capabilities Checks
WordPress Orbit Fox by ThemeIsle plugin <= 2.10.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress Orbit Fox by ThemeIsle plugin <= 2.10.2 - Authenticated Privilege Escalation vulnerability
CVE-2021-24158
CVE-2021-24157