NA

CVE-2023-2287

Published: 30/05/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Orbit Fox by ThemeIsle WordPress plugin prior to 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

themeisle orbitfox