The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versions up to, and including, 2.10.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 16,888 live websites that are affected by CVE-2024-2484.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 16,888 live websites (77.93% of OrbitFox install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 133 versions ( 84.71% of all versions) |
![]() | 4,235 websites |
![]() | 2,060 websites |
![]() | 1,721 websites |
![]() | 866 websites |
![]() | 631 websites |
![]() | 552 websites |
![]() | 522 websites |
![]() | 472 websites |
![]() | 456 websites |
![]() | 438 websites |
.com | 5,982 websites |
.de | 982 websites |
.org | 859 websites |
.fr | 737 websites |
.pl | 726 websites |
.nl | 640 websites |
.co.uk | 411 websites |
.it | 383 websites |
.net | 364 websites |
.ru | 349 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
***************.org | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
*******.com | ![]() | ***,*** | |
*********.com | ![]() | ***,*** | |
**********************.org | ![]() | ***,*** | |
***********.fr | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
*********.cz | ![]() | ***,*** |