First published: Mon Apr 05 2021(Updated: )
Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default for users upon registration. This field is hidden from view for lower-level users, however, they can still supply the user_role parameter to update the default role for registration.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeisle Orbit Fox | <2.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24158 is a vulnerability in the Orbit Fox plugin by ThemeIsle that allows attackers to set a default user role upon registration.
Orbit Fox plugin versions up to and excluding 2.10.3 for WordPress are affected by CVE-2021-24158.
The severity of CVE-2021-24158 is medium with a CVSS score of 6.5.
To fix CVE-2021-24158, update your Orbit Fox plugin to version 2.10.3 or higher.
You can find more information about CVE-2021-24158 at the following references: [Wordfence Blog](https://www.wordfence.com/blog/2021/01/multiple-vulnerabilities-patched-in-orbit-fox-by-themeisle-plugin/) and [WPScan](https://wpscan.com/vulnerability/d81d0e72-9bb5-47ef-a796-3b305a4b604f).