VendorsThemeisleorbit_foxany version
Vulnerabilities

Themeisle Orbit Fox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2021-24158
Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Privilege Escalation
Published 2021-04-05 · Modified
6.5EPSS 0.009
CVE-2025-22659
WordPress Orbit Fox by ThemeIsle plugin <= 2.10.44 - Cross Site Scripting (XSS) vulnerability
Published 2025-03-27 · Modified
6.5EPSS 0.003
CVE-2024-1497
Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via form widget addr2_width attribute
Published 2024-03-13 · Modified
6.4EPSS 0.005
CVE-2024-1499
Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-03-13 · Modified
6.4EPSS 0.005
CVE-2024-0508
Orbit Fox by ThemeIsle <= 2.10.27 - Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget
Published 2024-02-05 · Modified
6.4EPSS 0.005
CVE-2024-13183
Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag Parameter
Published 2025-01-10 · Analyzed
6.4EPSS 0.005
CVE-2024-1323
Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-02-27 · Modified
6.4EPSS 0.005
CVE-2024-2126
Orbit Fox by ThemeIsle <= 2.10.32 - Authenticated (Contributor+) Stored Cross-Site Scripiting via Registration Form Widget
Published 2024-03-13 · Modified
6.4EPSS 0.004
CVE-2023-6781
Orbit Fox Companion <= 2.10.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via custom fields
Published 2024-01-11 · Modified
6.4EPSS 0.004
CVE-2024-2484
Orbit Fox by ThemeIsle <= 2.10.34 - Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets
Published 2024-06-22 · Modified
6.4EPSS 0.004
CVE-2025-0311
Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget
Published 2025-01-10 · Analyzed
6.4EPSS 0.003
CVE-2024-7778
Orbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Published 2024-08-22 · Analyzed
6.4EPSS 0.003
CVE-2021-24157
Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Stored Cross Site Scripting
Published 2021-04-05 · Modified
5.4EPSS 0.007
CVE-2024-1047
ThemeIsle SDK <= Various Versions - Missing Authorization
Published 2024-02-02 · Modified
5.3EPSS 0.006
CVE-2024-1162
Orbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request Forgery
Published 2024-02-02 · Modified
4.3EPSS 0.002