CVE-2024-0508: Orbit Fox by ThemeIsle <= 2.10.27 - Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all versions up to, and including, 2.10.27 due to insufficient input sanitization and output escaping on the user supplied link URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0508?
The severity of CVE-2024-0508 is considered high due to the potential for stored cross-site scripting (XSS).
How do I fix CVE-2024-0508?
To fix CVE-2024-0508, update the Orbit Fox by ThemeIsle plugin to a version higher than 2.10.27 which includes security patches.
What is affected by CVE-2024-0508?
CVE-2024-0508 affects the Orbit Fox by ThemeIsle plugin for WordPress in all versions up to and including 2.10.27.
Can CVE-2024-0508 be exploited remotely?
Yes, CVE-2024-0508 can be exploited remotely since it involves user-supplied input that is not properly sanitized.
Who is responsible for patching CVE-2024-0508?
The responsibility for patching CVE-2024-0508 lies with the website administrators using the affected plugin, as developers will release updates to address the vulnerability.