Vulnerability Description
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Themeisle | Orbit Fox | < 2.10.44 |
Related Weaknesses (CWE)
References
- https://github.com/Codeinwp/themeisle-companion/commit/47a17c86934cebbfc3f1a812fPatch
- https://plugins.trac.wordpress.org/browser/themeisle-companion/trunk/obfx_modulePatch
- https://plugins.trac.wordpress.org/changeset/3219568/Patch
- https://wordpress.org/plugins/themeisle-companion/#developersRelease Notes
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d0f6be2b-5eb6-4828-ae9Third Party Advisory
FAQ
What is CVE-2024-13183?
CVE-2024-13183 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sanit...
How severe is CVE-2024-13183?
CVE-2024-13183 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-13183?
Check the references section above for vendor advisories and patch information. Affected products include: Themeisle Orbit Fox.