CVE-2025-10874

MEDIUM

Orbit Fox <3.0.2 - SSRF

Title source: llm

Description

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

Exploits (1)

github WORKING POC
by ryanmroth · pythonpoc
https://github.com/ryanmroth/Orbit-Fox_SSRF_CVE-2025-10874

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 10.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Details

CWE
CWE-918
Status published
Products (1)
Unknown/Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More < 3.0.2
Published Oct 24, 2025
Tracked Since Feb 18, 2026