Executive brief
Orbit Fox is a WordPress plugin that adds various features like menu icons, cookie notices, and custom fonts to websites. A security vulnerability in this plugin allows users with administrative access to inject malicious scripts into the site's settings. This could lead to unauthorized actions or data theft when other users visit the affected pages, particularly in multi-site environments where certain security restrictions are in place.
Technical details
The Orbit Fox plugin for WordPress (versions up to and including 3.0.6) contains a Stored Cross-Site Scripting (XSS) vulnerability within its administrative settings. The root cause is a failure to properly sanitize user input and escape output in the 'menu-icons' module. An authenticated attacker with administrator-level permissions can inject arbitrary JavaScript into the database. This script then executes in the browser of any user accessing the affected administrative pages. The vulnerability specifically impacts WordPress multi-site installations or single-site installations where the 'unfiltered_html' capability has been explicitly disabled for administrators. A patch was introduced in versions following 3.0.6.
Affected products
- ThemeIsle Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory
References
- https://plugins.trac.wordpress.org/browser/themeisle-companion/tags/3.0.5/obfx_modules/menu-icons/init.php
- https://plugins.trac.wordpress.org/browser/themeisle-companion/tags/3.0.5/obfx_modules/menu-icons/init.php
- https://plugins.trac.wordpress.org/browser/themeisle-companion/tags/3.0.6/obfx_modules/menu-icons/init.php
- https://plugins.trac.wordpress.org/browser/themeisle-companion/tags/3.0.6/obfx_modules/menu-icons/init.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3574306%40themeisle-companion&new=3574306%40themeisle-companion&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/beb1268c-b680-4ebe-8fe2-65f656390038?source=cve