CVE · Medium

CVE-2021-24157 — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24157 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.3 2.10.3 2021-01-12

CVE-2021-24157

The Orbit Fox plugin allowed users without the unfiltered_html capability to inject arbitrary scripts into page and post headers and footers because the plugin failed to validate user permissions before saving script tags. This vulnerability could enable lower-privileged users to execute malicious scripts on the site. The issue affected versions 2.10.2 and earlier and was resolved in version 2.10.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.