The Orbit Fox plugin for WordPress, created by ThemeIsle, has a security issue called Stored Cross-Site Scripting. This can happen when the form widget’s “addr2_width” attribute is not properly checked and cleaned. This allows attackers who are logged in with contributor or higher access to add harmful web scripts to pages. Whenever a user visits one of these pages, the script will be executed.