CVE-2026-16583
Received Received - Intake

Stored XSS in Orbit Fox WordPress Plugin via SVG Upload

Vulnerability report for CVE-2026-16583, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: WPScan

Description

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfiltered_html capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
themeisle orbit_fox to 3.0.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Orbit Fox WordPress plugin before version 3.0.8 has a stored XSS vulnerability due to improper sanitization of uploaded SVG files. Authenticated users with upload capabilities (Author role and above, excluding those without unfiltered_html) can upload SVG files containing JavaScript. When viewed, the JavaScript executes in the site context, enabling stored XSS attacks.

Detection Guidance

Check if the Orbit Fox plugin version is below 3.0.8. Inspect uploaded SVG files for embedded JavaScript or unusual content. Review user roles with upload capabilities for unauthorized SVG uploads.

Impact Analysis

An attacker could exploit this to execute malicious JavaScript on your WordPress site, potentially stealing user sessions, defacing the site, or redirecting visitors to harmful pages. It requires an authenticated user with upload permissions but could lead to broader site compromise if exploited.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR (data protection) and HIPAA (health data security) by exposing sensitive user information. Compliance may be compromised if user data is accessed or modified due to the XSS attack.

Mitigation Strategies

Update the Orbit Fox plugin to version 3.0.8 or later immediately. Disable SVG upload functionality if not required. Restrict upload permissions to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16583. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart