CVE Database /
CVE-2024-1162
CVE · Medium
CVE-2024-1162 — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.30
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-1162
|
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.30 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 2.10.30
|
2.10.30 |
2024-02-01 |
—
|
CVE-2024-1162
The Orbit Fox plugin by ThemeIsle contained a cross-site request forgery vulnerability that could allow an attacker to trick authenticated users with higher privileges into performing unintended actions. Francesco Carlucci identified and reported this flaw, which affected all versions prior to 2.10.30. The vulnerability was patched in version 2.10.30 and users should update immediately to this or any later version.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings