The Orbit Fox plugin for WordPress, created by ThemeIsle, has a security issue that can allow unauthorized users to inject harmful code into website pages. This can happen when uploading an SVG file, and it affects all versions of the plugin up to 2.10.36. This vulnerability can only be exploited by users with Author-level access or higher.