CVE-2024-1047
- EPSS 0.21%
- Veröffentlicht 02.02.2024 06:15:45
- Zuletzt bearbeitet 21.11.2024 08:49:40
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in all versions up to, and including, 2.10.28. This makes it possible for unauth...
CVE-2024-1162
- EPSS 0.12%
- Veröffentlicht 02.02.2024 06:15:45
- Zuletzt bearbeitet 21.11.2024 08:49:56
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due to missing or incorrect nonce validation on the register_reference() function. This makes it possib...
CVE-2023-6781
- EPSS 0.15%
- Veröffentlicht 11.01.2024 09:15:52
- Zuletzt bearbeitet 21.11.2024 08:44:33
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 2.10.26 due to insufficient input sanitization and output escaping on user supplied valu...
CVE-2021-24157
- EPSS 0.18%
- Veröffentlicht 05.04.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:52:29
Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to i...
CVE-2021-24158
- EPSS 0.19%
- Veröffentlicht 05.04.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:52:29
Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default for users upon registra...