The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.
We have discovered 16,146 live websites that are affected by CVE-2023-2287.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 16,146 live websites (74.51% of OrbitFox install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 122 versions ( 77.71% of all versions) |
![]() | 4,070 websites |
![]() | 1,963 websites |
![]() | 1,643 websites |
![]() | 839 websites |
![]() | 609 websites |
![]() | 528 websites |
![]() | 507 websites |
![]() | 445 websites |
![]() | 431 websites |
![]() | 413 websites |
.com | 5,755 websites |
.de | 939 websites |
.org | 807 websites |
.pl | 708 websites |
.fr | 706 websites |
.nl | 614 websites |
.co.uk | 396 websites |
.it | 354 websites |
.net | 347 websites |
.ru | 325 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
***************.org | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
*******.com | ![]() | ***,*** | |
*********.com | ![]() | ***,*** | |
**********************.org | ![]() | ***,*** | |
***********.fr | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
*********.cz | ![]() | ***,*** |
FAQ