๐Ÿ” CVE Alert

CVE-2026-85418

MEDIUM 5.4

Orbit Fox < 3.0.9 - Contributor+ Stored XSS via Beaver Builder Pricing Table Widget

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9 does not validate a user-supplied HTML tag name in one of its Beaver Builder widgets before echoing it into the rendered markup, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when any visitor views the affected page.

Vendor unknown
Product orbit fox: duplicate page, menu icons, svg support, cookie notice, custom fonts & more
Published Sep 9, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown orbit fox: duplicate page, menu icons, svg support, cookie notice, custom fonts & more

Be the first to know when new medium vulnerabilities affecting unknown orbit fox: duplicate page, menu icons, svg support, cookie notice, custom fonts & more are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
0 < 3.0.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/8f9ba009-324f-46ef-853f-9f2e706c401e/

Credits

Farid Narimanov WPScan