The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in the $settings['title_tags'] parameter in all versions up to, and including, 2.10.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 16,763 live websites that are affected by CVE-2024-1499.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 16,763 live websites (77.35% of OrbitFox install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 129 versions ( 82.17% of all versions) |
![]() | 4,214 websites |
![]() | 2,047 websites |
![]() | 1,707 websites |
![]() | 860 websites |
![]() | 628 websites |
![]() | 549 websites |
![]() | 520 websites |
![]() | 466 websites |
![]() | 453 websites |
![]() | 435 websites |
.com | 5,946 websites |
.de | 975 websites |
.org | 854 websites |
.fr | 732 websites |
.pl | 724 websites |
.nl | 637 websites |
.co.uk | 411 websites |
.it | 379 websites |
.net | 360 websites |
.ru | 346 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
***************.org | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
*******.com | ![]() | ***,*** | |
*********.com | ![]() | ***,*** | |
**********************.org | ![]() | ***,*** | |
***********.fr | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
*********.cz | ![]() | ***,*** |