CVE Database /
CVE-2023-2287
CVE · Medium
CVE-2023-2287 — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.24
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-2287
|
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.24 |
Server-Side Request Forgery (SSRF) |
Medium
4.3
|
< 2.10.24
|
2.10.24 |
2023-04-27 |
—
|
CVE-2023-2287
The Orbit Fox plugin for WordPress is vulnerable to Server-Side Request Forgery through its parse_request function in versions 2.10.23 and earlier. Attackers with authenticated access and upload_files capability, including authors and higher roles, can exploit this flaw to initiate web requests from the server to arbitrary destinations. This vulnerability allows attackers to access or manipulate data from internal services that would normally be restricted from external access.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings