CVE-2025-10874
MEDIUMOrbit Fox <3.0.2 - SSRF
Title source: llmDescription
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.
Exploits (1)
github
WORKING POC
by ryanmroth · pythonpoc
https://github.com/ryanmroth/Orbit-Fox_SSRF_CVE-2025-10874
Scores
CVSS v3
5.5
EPSS
0.0004
EPSS Percentile
10.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Details
CWE
CWE-918
Status
published
Products (1)
Unknown/Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
< 3.0.2
Published
Oct 24, 2025
Tracked Since
Feb 18, 2026