CVE-2025-10874: Orbit Fox < 3.0.2 - Author+ Server-Side Request Forgery
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10874?
CVE-2025-10874 is considered a medium severity vulnerability due to its potential for server-side request forgery attacks.
How do I fix CVE-2025-10874?
To fix CVE-2025-10874, you should upgrade the Orbit Fox WordPress plugin to version 3.0.2 or later.
What are the impacts of CVE-2025-10874?
CVE-2025-10874 allows an attacker to use arbitrary URLs with the stock photo import feature, leading to server-side request forgery.
Who is affected by CVE-2025-10874?
Users of the Orbit Fox WordPress plugin prior to version 3.0.2 are affected by CVE-2025-10874.
Is CVE-2025-10874 being actively exploited?
As of now, there is no public information indicating that CVE-2025-10874 is being actively exploited.