Input validation vulnerability in Catch Dark Mode 2.0

The Catch Dark Mode plugin for WordPress has a security issue that affects all versions up to version 2.0. This issue allows attackers with Contributor-level access or higher to include and run any .php files on the server. This can lead to bypassing security measures, accessing confidential information, or executing malicious code if .php files are allowed to be uploaded and included.

Detected in:

Catch Dark Mode fixed vulnerable versions: >= * <= 2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.