Input validation vulnerability in Dark Mode for WP Dashboard 1.2.3

The Dark Mode for WP Dashboard plugin used in WordPress is not secure and can be taken advantage of by hackers. This is because it does not properly check for verification codes before allowing changes to be made by the dark_mode_dashboard_change_user_profile_mode() function. As a result, unauthorized individuals could potentially alter a user’s color settings by tricking a site administrator into clicking on a deceptive link.

Detected in:

Dark Mode for WP Dashboard fixed vulnerable versions: >= * <= 1.2.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.