CVE · Medium

CVE-2022-4714 — WP Dark Mode – Improve Accessibility with AI Powered Dark Theme [wp-dark-mode] < 4.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4714 WP Dark Mode – Improve Accessibility with AI Powered Dark Theme [wp-dark-mode] < 4.0.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.0.0 4.0.0 2023-01-30

CVE-2022-4714

The WP Dark Mode plugin before version 4.0.0 contains a cross-site scripting vulnerability that could permit an attacker to inject malicious scripts into a website, which would execute when visitors access the site. The injected code could include redirects, ads, or other HTML content. This flaw was patched in version 4.0.0 and users should upgrade to that version or later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.