Input validation vulnerability in Dracula Dark Mode – Enhanced Accessibility, Dark Mode & Reading Mode for WordPress 1.0.8

The Dracula Dark Mode plugin for WordPress, which adds features like Enhanced Accessibility, Dark Mode, and Reading Mode, has a security flaw. This vulnerability, called Stored Cross-Site Scripting, allows attackers with certain levels of access to add harmful code to web pages. This can happen in any version of the plugin up to version 1.0.8, because the plugin does not properly clean or protect against user-inputted attributes. To protect against this vulnerability, it is recommended to update the plugin to a newer version.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.