CyberRota Analysis
AI-GeneratedThe Orbit Fox plugin for WordPress prior to version 3.0.9 is vulnerable due to insufficient validation of user-supplied HTML tag names in its Beaver Builder widgets, enabling users with contributor-level access or higher to inject malicious scripts. This flaw can lead to cross-site scripting (XSS) attacks, potentially compromising the security of visitors to affected pages. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9 does not validate a user-supplied HTML tag name in one of its Beaver Builder widgets before echoing it into the rendered markup, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when any visitor views the affected page.