WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More

Add modules: share buttons, header/footer scripts, disable comments, reading progress, custom fonts, custom login & more in one plugin.

21Reported vulnerabilities
9.9Highest CVSS score
3.0.9Latest version
100,000+Active installs

What to do now

Update Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More to 3.0.8 or later. 21 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 30, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-24158 Critical 9.9 0.9% Before 2.10.3 2.10.3 November 24, 2020
WF-f53e5192-e809-400c-aed9-36b5d6415a9d High 7.3 2.6.3 and earlier 2.6.4 November 12, 2018
CVE-2025-22659 Medium 6.4 0.3% 2.10.44 and earlier 2.10.45 February 3, 2025
CVE-2021-24157 Medium 6.4 0.7% Before 2.10.3 2.10.3 January 12, 2021
CVE-2026-16583 Medium 6.4 0.2% 3.0.7 and earlier 3.0.8 July 27, 2026
CVE-2026-65563 Medium 6.4 0.1% 3.0.7 and earlier 3.0.8 July 24, 2026
CVE-2025-12045 Medium 6.4 0.2% 0 to 3.0.2 (inclusive) 3.0.3 November 4, 2025
CVE-2025-10874 Medium 6.4 0.2% 3.0.1 and earlier 3.0.2 October 3, 2025
CVE-2025-58593 Medium 6.4 0.2% 3.0.0 and earlier 3.0.1 September 3, 2025
CVE-2024-13183 Medium 5.4 0.5% Before 2.10.44 2.10.44 January 10, 2025
CVE-2025-0311 Medium 5.4 0.3% Before 2.10.44 2.10.44 January 10, 2025
CVE-2024-7778 Medium 5.4 0.3% Before 2.10.37 2.10.37 August 22, 2024
CVE-2024-2484 Medium 5.4 0.4% Before 2.10.35 2.10.35 June 22, 2024
CVE-2024-2126 Medium 5.4 0.4% Before 2.10.33 2.10.33 March 13, 2024
CVE-2024-1499 Medium 5.4 0.5% Before 2.10.31 2.10.31 March 13, 2024
CVE-2024-1497 Medium 5.4 0.5% Before 2.10.31 2.10.31 March 13, 2024
CVE-2024-1323 Medium 5.4 0.5% Before 2.10.31 2.10.31 February 27, 2024
CVE-2024-0508 Medium 5.4 0.5% 2.10.27 and earlier 2.10.28 February 5, 2024
CVE-2024-1047 Medium 5.3 0.6% 2.10.28 and earlier 32.0.10 February 2, 2024
CVE-2023-6781 Medium 5.4 0.4% 2.10.26 and earlier 2.10.27 January 11, 2024
CVE-2026-11358 Medium 4.4 0.3% 0 to 3.0.6 (inclusive) 3.0.7 June 18, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.