---
id: CVE-2025-10874
title: >-
  The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom
  Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be
  used for the stock photo import feature, allowing the user to specify
  arbitrary URL…
summary: >-
  The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom
  Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be
  used for the stock photo import feature, allowing the user to specify
  arbitrary URL…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-918
published: '2025-10-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10874'
references:
  - url: 'https://wpscan.com/vulnerability/171ba43f-55b6-471d-af0a-be553baf639a/'
    label: contact@wpscan.com
tags:
  - nvd
  - exploit-available
epss: 0.0019
epssPercentile: 0.0792
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/ryanmroth/Orbit-Fox_SSRF_CVE-2025-10874'
  checkedAt: '2026-10-08T11:32:03.419Z'
exploitAvailable: true
ingestedAt: '2026-10-08T11:31:27.565Z'
---

## Overview

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
