CVE-2023-0467
The WP Dark Mode plugin contains a local file inclusion vulnerability in versions 4.0.7 and earlier through the 'style' shortcode parameter that permits authenticated users with subscriber privileges or higher to load and execute arbitrary files from the server. Attackers can exploit this flaw to run PHP code contained in uploaded files, potentially circumventing security measures, accessing confidential information, or executing malicious code. The vulnerability only manifests when the server permits directory traversal to non-existent paths or when combined with a separate flaw enabling arbitrary directory creation. Updating to version 4.0.8 or later resolves this issue.
Based on public CVE data (MITRE/NVD).