CVE · Medium

CVE-2024-1497 — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.31

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1497 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.31 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.31 2.10.31 2024-02-26

CVE-2024-1497

The Orbit Fox by ThemeIsle plugin through version 2.10.30 contains a stored cross-site scripting vulnerability in the form widget's addr2_width attribute caused by inadequate sanitization of user input and improper escaping of output. Authenticated users with contributor-level permissions or above can inject malicious scripts into pages, which execute for any visitor viewing those pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.