PLUGIN SECURITY

Is Themeisle Companion safe?

Add modules: share buttons, header/footer scripts, disable comments, reading progress, custom fonts, custom login & more in one plugin.

What this plugin does

  • Slug: themeisle-companion
  • Author: Themeisle
  • 100000+ active installs
  • 96/100 rating (317 reviews on wordpress.org)
  • 13929410 all-time downloads
  • On WordPress.org since 2016-11-03

cookie noticeduplicate pagelogin customizershare buttonssvg support

Maintenance status

  • Latest known version: 3.0.9
  • Last updated: 2026-08-20 6:37pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

22 known CVEs on file for Themeisle Companion.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16583 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.0.8 3.0.8 2026-07-27 ✓ fixed in latest
CVE-2026-11358 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.4 < 3.0.7 3.0.7 2026-06-17 ✓ fixed in latest
CVE-2025-12045 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.0.3 3.0.3 2025-11-03 ✓ fixed in latest
CVE-2025-10874 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.2 Server-Side Request Forgery (SSRF) Medium 5.5 < 3.0.2 3.0.2 2025-10-03 ✓ fixed in latest
CVE-2025-58593 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.0.1 3.0.1 2025-09-03 ✓ fixed in latest
CVE-2025-22659 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.45 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.10.45 2.10.45 2025-02-03 ✓ fixed in latest
CVE-2024-13183 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.44 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.10.44 2.10.44 2025-01-09 ✓ fixed in latest
CVE-2024-7778 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.37 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.37 2.10.37 2024-08-21 ✓ fixed in latest
+ 23 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2484 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.35 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.35 2.10.35 2024-06-21 ✓ fixed in latest
CVE-2024-2126 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.33 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.33 2.10.33 2024-03-07 ✓ fixed in latest
CVE-2024-1323 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.32 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.32 2.10.32 2024-02-26 ✓ fixed in latest
CVE-2024-1499 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.31 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.31 2.10.31 2024-02-26 ✓ fixed in latest
CVE-2024-1497 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.31 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.31 2.10.31 2024-02-26 ✓ fixed in latest
CVE-2024-1047 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.29 Missing Authorization Medium 5.3 < 2.10.29 2.10.29 2024-02-01 ✓ fixed in latest
CVE-2024-1162 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.30 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.10.30 2.10.30 2024-02-01 ✓ fixed in latest
CVE-2024-0508 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.28 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.28 2.10.28 2024-01-15 ✓ fixed in latest
CVE-2023-6781 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.27 Improper Input Validation Medium 5.4 < 2.10.27 2.10.27 2024-01-05 ✓ fixed in latest
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.24 Unknown < 2.10.24 2.10.24 2023-04-27 ✓ fixed in latest
CVE-2023-2287 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.24 Server-Side Request Forgery (SSRF) Medium 4.3 < 2.10.24 2.10.24 2023-04-27 ✓ fixed in latest
CVE-2021-24157 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.3 2.10.3 2021-01-12 ✓ fixed in latest
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3 Unknown < 2.10.3 2.10.3 2021-01-12 ✓ fixed in latest
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3 Unknown < 2.10.3 2.10.3 2021-01-12 ✓ fixed in latest
CVE-2021-24158 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.3 Improper Privilege Management Medium 6.5 < 2.10.3 2.10.3 2020-11-24 ✓ fixed in latest
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.6.4 Unknown < 2.6.4 2.6.4 2018-11-12 ✓ fixed in latest
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.44 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.10.44 2.10.44 0000-00-00 ✓ fixed in latest
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.8 Unknown < 3.0.8 3.0.8 0000-00-00 ✓ fixed in latest
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.6.4 Unknown < 2.6.4 2.6.4 ✓ fixed in latest
Orbit Fox by ThemeIsle <= 2.6.3 -Does not properly Authenticate REST API Calls Unknown < 2.6.4 2.6.4 ✓ fixed in latest
CVE-2024-0508 Orbit Fox by ThemeIsle < 2.10.28 - Contributor+ Stored XSS Unknown < 2.10.28 2.10.28 ✓ fixed in latest
CVE-2025-0311 Orbit Fox by ThemeIsle < 2.10.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget Unknown < 2.10.44 2.10.44 ✓ fixed in latest
CVE-2026-65563 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More < 3.0.8 - Authenticated (Author+) Stored Cross-Site Scripting Unknown < 3.0.8 3.0.8 ✓ fixed in latest

How to fix it

Keep Themeisle Companion updated — 3.0.9 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.