comparemela.com


minute read
Share this article:
Two security vulnerabilities — one a privilege-escalation problem and the other a stored XSS bug — afflict a WordPress plugin with 40,000 installs.
Two vulnerabilities (one critical) in a WordPress plugin called Orbit Fox could allow attackers to inject malicious code into vulnerable websites and/or take control of a website.
Orbit Fox is a multi-featured WordPress plugin that works with the Elementor, Beaver Builder and Gutenberg site-building utilities. It allows site administrators to add features such as registration forms and widgets. The plugin, from a developer called ThemeIsle, has been installed by 400,000+ sites.
According to researchers at Wordfence, the first flaw (CVEs are pending) is an authenticated privilege-escalation flaw that carries a CVSS bug-severity score of 9.9, making it critical. Authenticated attackers with contributor level access or above can elevate themselves to administrator status and potentially take over a WordPress site.

Related Keywords

,Team Showcase ,Wordpress ,Orbit Fox ,Beaver Builder ,Share Your Feedback ,Post Grid ,Hacks ,Malware ,Vulnerabilities ,Web Security ,Mobile Security ,Privacy ,Security Vulnerabilities ,Plug In ,Cross Site Scripting ,Privilege Escalation ,Website ,Takeover ,அணி காட்சி பெட்டி ,வேர்ட்பிரஸ் ,ஆர்‌பிட் நரி ,பீவர் பில்டர் ,பகிர் உங்கள் பின்னூட்டம் ,போஸ்ட் கட்டம் ,ஹேக்ஸ் ,தீம்பொருள் ,வலை பாதுகாப்பு ,கைபேசி பாதுகாப்பு ,ப்ரைவஸீ ,ப்லக் இல் ,குறுக்கு தளம் ஸ்கிரிப்டிங் ,இணையதளம் ,கையகப்படுத்தல் ,

© 2025 Vimarsana

comparemela.com © 2020. All Rights Reserved.