PLUGIN SECURITY
Is Themeisle Companion safe?
Add modules: share buttons, header/footer scripts, disable comments, reading progress, custom fonts, custom login & more in one plugin.
What this plugin does
- Slug:
themeisle-companion - Author: Themeisle
- 100000+ active installs
- 96/100 rating (317 reviews on wordpress.org)
- 13929410 all-time downloads
- On WordPress.org since 2016-11-03
cookie noticeduplicate pagelogin customizershare buttonssvg support
Maintenance status
- Latest known version: 3.0.9
- Last updated: 2026-08-20 6:37pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
22 known CVEs on file for Themeisle Companion.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-16583 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 3.0.8 | 3.0.8 | 2026-07-27 | ✓ fixed in latest |
| CVE-2026-11358 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.4 | < 3.0.7 | 3.0.7 | 2026-06-17 | ✓ fixed in latest |
| CVE-2025-12045 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.0.3 | 3.0.3 | 2025-11-03 | ✓ fixed in latest |
| CVE-2025-10874 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.2 | Server-Side Request Forgery (SSRF) | Medium 5.5 | < 3.0.2 | 3.0.2 | 2025-10-03 | ✓ fixed in latest |
| CVE-2025-58593 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.0.1 | 3.0.1 | 2025-09-03 | ✓ fixed in latest |
| CVE-2025-22659 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.45 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.10.45 | 2.10.45 | 2025-02-03 | ✓ fixed in latest |
| CVE-2024-13183 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.44 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.10.44 | 2.10.44 | 2025-01-09 | ✓ fixed in latest |
| CVE-2024-7778 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.37 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.10.37 | 2.10.37 | 2024-08-21 | ✓ fixed in latest |
+ 23 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-2484 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.35 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.10.35 | 2.10.35 | 2024-06-21 | ✓ fixed in latest |
| CVE-2024-2126 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.33 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.10.33 | 2.10.33 | 2024-03-07 | ✓ fixed in latest |
| CVE-2024-1323 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.32 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.10.32 | 2.10.32 | 2024-02-26 | ✓ fixed in latest |
| CVE-2024-1499 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.31 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.10.31 | 2.10.31 | 2024-02-26 | ✓ fixed in latest |
| CVE-2024-1497 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.31 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.10.31 | 2.10.31 | 2024-02-26 | ✓ fixed in latest |
| CVE-2024-1047 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.29 | Missing Authorization | Medium 5.3 | < 2.10.29 | 2.10.29 | 2024-02-01 | ✓ fixed in latest |
| CVE-2024-1162 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.30 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 2.10.30 | 2.10.30 | 2024-02-01 | ✓ fixed in latest |
| CVE-2024-0508 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.28 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.10.28 | 2.10.28 | 2024-01-15 | ✓ fixed in latest |
| CVE-2023-6781 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.27 | Improper Input Validation | Medium 5.4 | < 2.10.27 | 2.10.27 | 2024-01-05 | ✓ fixed in latest |
| — | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.24 | — | Unknown | < 2.10.24 | 2.10.24 | 2023-04-27 | ✓ fixed in latest |
| CVE-2023-2287 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.24 | Server-Side Request Forgery (SSRF) | Medium 4.3 | < 2.10.24 | 2.10.24 | 2023-04-27 | ✓ fixed in latest |
| CVE-2021-24157 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.10.3 | 2.10.3 | 2021-01-12 | ✓ fixed in latest |
| — | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3 | — | Unknown | < 2.10.3 | 2.10.3 | 2021-01-12 | ✓ fixed in latest |
| — | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3 | — | Unknown | < 2.10.3 | 2.10.3 | 2021-01-12 | ✓ fixed in latest |
| CVE-2021-24158 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3 | Improper Privilege Management | Medium 6.5 | < 2.10.3 | 2.10.3 | 2020-11-24 | ✓ fixed in latest |
| — | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.6.4 | — | Unknown | < 2.6.4 | 2.6.4 | 2018-11-12 | ✓ fixed in latest |
| — | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.44 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.10.44 | 2.10.44 | 0000-00-00 | ✓ fixed in latest |
| — | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.8 | — | Unknown | < 3.0.8 | 3.0.8 | 0000-00-00 | ✓ fixed in latest |
| — | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.6.4 | — | Unknown | < 2.6.4 | 2.6.4 | — | ✓ fixed in latest |
| — | Orbit Fox by ThemeIsle <= 2.6.3 -Does not properly Authenticate REST API Calls | — | Unknown | < 2.6.4 | 2.6.4 | — | ✓ fixed in latest |
| CVE-2024-0508 | Orbit Fox by ThemeIsle < 2.10.28 - Contributor+ Stored XSS | — | Unknown | < 2.10.28 | 2.10.28 | — | ✓ fixed in latest |
| CVE-2025-0311 | Orbit Fox by ThemeIsle < 2.10.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget | — | Unknown | < 2.10.44 | 2.10.44 | — | ✓ fixed in latest |
| CVE-2026-65563 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More < 3.0.8 - Authenticated (Author+) Stored Cross-Site Scripting | — | Unknown | < 3.0.8 | 3.0.8 | — | ✓ fixed in latest |
How to fix it
Keep Themeisle Companion updated — 3.0.9 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Duplicate Page — 3000000+ active installs — 96/100 (465)
- CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice) — 1000000+ active installs — 96/100 (3228) — max PHP 8.4
- Complianz GDPR/CCPA Cookie Consent Banner — 1000000+ active installs — 94/100 (1655) — max PHP 8.4
- WPConsent – Cookie Banner & Cookie Consent for Privacy Compliance (GDPR / CCPA / EU Compliance Cookie Notice) — 200000+ active installs — 98/100 (78)
- Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode — 100000+ active installs — 88/100 (438)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.