Cross-Site Scripting Vulnerability in Dark Mode Plugin for WordPress
CVE-2018-5651
4.8MEDIUM
What is CVE-2018-5651?
An XSS vulnerability exists in the Dark Mode Plugin version 1.6 for WordPress. This issue is triggered via the 'dark_mode_start' parameter in the wp-admin/profile.php file, allowing attackers to inject malicious scripts. Successful exploitation could lead to unauthorized access to sensitive information or execution of unauthorized actions within the WordPress admin interface.