CVE · Medium

CVE-2023-0467 — WP Dark Mode – Improve Accessibility with AI Powered Dark Theme [wp-dark-mode] < 4.0.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0467 WP Dark Mode – Improve Accessibility with AI Powered Dark Theme [wp-dark-mode] < 4.0.8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.3 < 4.0.8 4.0.8 2023-03-06

CVE-2023-0467

The WP Dark Mode plugin contains a local file inclusion vulnerability in versions 4.0.7 and earlier through the 'style' shortcode parameter that permits authenticated users with subscriber privileges or higher to load and execute arbitrary files from the server. Attackers can exploit this flaw to run PHP code contained in uploaded files, potentially circumventing security measures, accessing confidential information, or executing malicious code. The vulnerability only manifests when the server permits directory traversal to non-existent paths or when combined with a separate flaw enabling arbitrary directory creation. Updating to version 4.0.8 or later resolves this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.