The Orbit Fox by ThemeIsle is a plugin for WordPress that has a security vulnerability. This means that hackers can insert harmful code into pages using the plugin’s Pricing Table Elementor Widget. This can happen in all versions up to 2.10.27. The vulnerability is caused by not properly checking and cleaning the link URL provided by the user. This means that people with certain permissions can insert code that will run whenever someone visits the affected page.