CVE-2026-85418
Orbit Fox < 3.0.9 - Contributor+ Stored XSS via Beaver Builder Pricing Table Widget
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9 does not validate a user-supplied HTML tag name in one of its Beaver Builder widgets before echoing it into the rendered markup, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when any visitor views the affected page.
| Vendor | unknown |
| Product | orbit fox: duplicate page, menu icons, svg support, cookie notice, custom fonts & more |
| Published | Sep 9, 2026 |
| Last Updated | Sep 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown orbit fox: duplicate page, menu icons, svg support, cookie notice, custom fonts & more
Be the first to know when new medium vulnerabilities affecting unknown orbit fox: duplicate page, menu icons, svg support, cookie notice, custom fonts & more are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
0 < 3.0.9
References
Credits
Farid Narimanov WPScan