CVE-2023-2287

Orbit Fox < 2.10.24 - Author+ Server-Side Request Forgery

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.


We have discovered 16,146 live websites that are affected by CVE-2023-2287.

Test my site




Affected Software

Product  OrbitFox
Category Wordpress Plugins
Vulnerable Domains16,146 live websites (74.51% of OrbitFox install base)
Vulnerable Versions
  • from 0 before 2.10.24
Vulnerable Versions Count122 versions ( 77.71% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - May 30, 2023
  • Updated - Jan 10, 2025

Credits

  • Alex Sanford (finder)
  • WPScan (coordinator)

CVE-2023-2287 usage by Country

United States4,070 websites



Germany1,963 websites
France1,643 websites
Poland839 websites
Netherlands609 websites
GB528 websites
Japan507 websites
Spain445 websites
Italy431 websites
Russia413 websites

CVE-2023-2287 usage by TLD

.com5,755 websites
.de939 websites
.org807 websites
.pl708 websites
.fr706 websites
.nl614 websites
.co.uk396 websites
.it354 websites
.net347 websites
.ru325 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2287

Top websites that are affected by CVE-2023-2287. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com Korea, South**,***
*******.com Germany**,***
***************.org United States***,***
*****************.com United States***,***
*******.com Cyprus***,***
*********.com Canada***,***
**********************.org United States***,***
***********.fr France***,***
***********.com Argentina***,***
*********.cz Czech Republic***,***
See full domain list

FAQ

CVE-2023-2287 is Server-Side Request Forgery (SSRF) in OrbitFox
A total of 16,146 websites have been identified as vulnerable to CVE-2023-2287, discovered through global website indexing conducted by WebTechSurvey.
OrbitFox is susceptible to CVE-2023-2287 vulnerability.
OrbitFox versions before 2.10.24 are vulnerable to CVE-2023-2287.
Version 2.10.24 of OrbitFox addresses the CVE-2023-2287 security vulnerability.