The Orbit Fox plugin for WordPress, created by ThemeIsle, is at risk for a type of hacking called Stored Cross-Site Scripting. This can happen in versions 2.10.44 and below because the plugin does not properly clean up user input and output. This vulnerability allows attackers with contributor-level permissions or higher to insert harmful web scripts into pages, which will run whenever someone visits the affected page.