CVE-2026-16583: Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfilteredhtml capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Orbit Fox by ThemeIsleto a version that resolves this vulnerability.Fixed in 3.0.8 - Configuration
Disable the plugin’s SVG upload feature to prevent authenticated users from uploading unsanitized SVG files that can execute JavaScript when viewed.
Orbit Fox by ThemeIsle WordPress plugin SVG upload feature (enable/disable) = disable
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16583?
CVE-2026-16583 has a risk rating of 40, indicating it is a medium severity vulnerability.
How do I fix CVE-2026-16583?
To fix CVE-2026-16583, update the Orbit Fox by ThemeIsle plugin to version 3.0.8 or higher.
Who is affected by CVE-2026-16583?
CVE-2026-16583 affects authenticated users with upload capabilities in the Orbit Fox plugin version before 3.0.8.
What type of vulnerability is CVE-2026-16583?
CVE-2026-16583 is a stored XSS vulnerability due to insufficient sanitization of uploaded SVG files.
What should I do if I cannot update to fix CVE-2026-16583?
If you cannot update, disable the SVG upload feature in the Orbit Fox plugin to mitigate CVE-2026-16583.