CVE · Medium

CVE-2023-2287 — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.24

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-2287 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.24 Server-Side Request Forgery (SSRF) Medium 4.3 < 2.10.24 2.10.24 2023-04-27

CVE-2023-2287

The Orbit Fox plugin for WordPress is vulnerable to Server-Side Request Forgery through its parse_request function in versions 2.10.23 and earlier. Attackers with authenticated access and upload_files capability, including authors and higher roles, can exploit this flaw to initiate web requests from the server to arbitrary destinations. This vulnerability allows attackers to access or manipulate data from internal services that would normally be restricted from external access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.